First published: Thu Jan 09 2025(Updated: )
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/etcd | <3.3.23-17.el8 | 3.3.23-17.el8 |
redhat/etcd-debuginfo | <3.3.23-17.el8 | 3.3.23-17.el8 |
redhat/etcd-debugsource | <3.3.23-17.el8 | 3.3.23-17.el8 |
Red Hat OpenStack | ||
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:0203 is classified as important.
To fix RHSA-2025:0203, update the affected packages to version 3.3.23-17.el8.
RHSA-2025:0203 addresses a stack exhaustion issue caused by calling Decoder.Decode on deeply nested structures (CVE-2024-34156).
The affected packages include etcd, etcd-debuginfo, and etcd-debugsource versions below 3.3.23-17.el8.
Yes, Red Hat OpenStack for IBM Power and Red Hat OpenStack products are impacted by RHSA-2025:0203.