RHSA-2025:0203: Important: Red Hat OpenStack Platform 16.2 (etcd) security update
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Other sources
Important: Red Hat OpenStack Platform 16.2 (etcd) security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0203?
The severity of RHSA-2025:0203 is classified as important.
How do I fix RHSA-2025:0203?
To fix RHSA-2025:0203, update the affected packages to version 3.3.23-17.el8.
What vulnerability is addressed by RHSA-2025:0203?
RHSA-2025:0203 addresses a stack exhaustion issue caused by calling Decoder.Decode on deeply nested structures (CVE-2024-34156).
Which software packages are affected by RHSA-2025:0203?
The affected packages include etcd, etcd-debuginfo, and etcd-debugsource versions below 3.3.23-17.el8.
Is any specific product impacted by RHSA-2025:0203?
Yes, Red Hat OpenStack for IBM Power and Red Hat OpenStack products are impacted by RHSA-2025:0203.