RHSA-2025:1190: Important: Red Hat OpenStack Platform 17.1 (etcd) security update
A highly-available key value store for shared configurationSecurity Fix(es): golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Other sources
Important: Red Hat OpenStack Platform 17.1 (etcd) security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:1190?
The severity of RHSA-2025:1190 is classified as important due to the potential for stack exhaustion leading to a panic.
How do I fix RHSA-2025:1190?
To fix RHSA-2025:1190, update the etcd, etcd-debuginfo, and etcd-debugsource packages to version 3.4.26-9.1.el9.
What software is affected by RHSA-2025:1190?
RHSA-2025:1190 affects the etcd, etcd-debuginfo, and etcd-debugsource packages in Red Hat Enterprise Linux 9.
What vulnerability does RHSA-2025:1190 address?
RHSA-2025:1190 addresses a vulnerability (CVE-2024-34156) that can cause a panic in the golang Decoder.Decode function on deeply nested messages.
Is there a workaround for RHSA-2025:1190?
As of now, there is no specific workaround for RHSA-2025:1190 other than applying the recommended updates.