Red Hat released fixes for three Go standard-library denial-of-service vulnerabilities: CVE-2024-34155 in go/parser, CVE-2024-34156 in encoding/gob, and CVE-2024-34158 in go/build/constraint. Applications that parse or decode attacker-controlled input can panic after deeply nested Go literals, gob structures, or legacy // +build expressions exhaust stack space. Red Hat rated the issues Important in affected product advisories; no exploitation evidence is identified in the supplied advisories.
The fixes were delivered through updated Go toolsets for RHEL 8 and RHEL 9 and propagated to container tooling including Podman, Buildah, CRI-O, and the RHEL 8 container-tools module. Red Hat also issued updated images and packages for OpenShift Container Platform 4.12 through 4.17, OpenShift API for Data Protection, OpenStack Platform, Migration Toolkit for Containers, and several OpenShift operators. Organizations should update affected systems, container tools, and OpenShift clusters through their applicable Red Hat release channels, including all supported x86_64, ARM64, IBM Power, and IBM Z/LinuxONE deployments.

See affected versions and whether adversaries are exploiting it.
29 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:7118 for osbuild 141-1.el9 and osbuild-composer 132-1.el9 on RHEL 9. The update remediated CVE-2024-1394, CVE-2024-34158, and the golang-fips zeroed-buffer flaw CVE-2024-9355.
Red Hat issued Important-severity advisory RHSA-2025:0654, releasing OpenShift Container Platform 4.17.14 container images for RHEL 8 and 9 across x86_64, ppc64le, s390x, and aarch64. The update remediated flaws including go-git argument injection and denial of service, DOMPurify prototype pollution, and parsing and validation issues in Go and JavaScript components.
RHSA-2025:0771 released OpenShift API for Data Protection 1.4.2 for RHEL 9. The update fixed CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158, which could cause denial of service through stack exhaustion.
RHSA-2024:10906 released Migration Toolkit for Containers 1.8.5 for RHEL 8 and fixed CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158 alongside other Go and JavaScript dependency vulnerabilities.
RHSA-2024:10883 supplied updated osp-director-operator-container images for Red Hat OpenStack Platform 16.2. The update remediated CVE-2024-34155 and CVE-2024-34156 denial-of-service conditions.
RHSA-2024:8704 released Kube Descheduler Operator 5.0.2 for RHEL 9, fixing CVE-2024-34155 and CVE-2024-34158 as well as the protojson infinite-loop issue CVE-2024-24786.
RHSA-2024:9960 released OpenShift API for Data Protection 1.3.4 for RHEL 9 and remediated CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158.
RHSA-2024:8219 updated Secondary Scheduler Operator for Red Hat OpenShift to version 1.2.2 for RHEL 9. It fixed CVE-2024-34155 and CVE-2024-34158, along with CVE-2024-24791.
Red Hat issued RHSA-2024:9485 for RHOSO 18.0.3 Feature Release 1, updating OpenStack Podified Control Plane Operators 1.0 on x86_64. The update remediated CVE-2024-34155 and CVE-2024-34156 along with multiple Go flaws affecting HTTP redirects, multipart parsing, certificate verification, templates, and DNS resolution.
Red Hat released OpenShift 4.12.68 images and packages through RHSA-2024:8692 and RHSA-2024:8694, and OpenShift 4.14.40 images through RHSA-2024:8697. Each update addressed the three Go stack-exhaustion vulnerabilities.
RHSA-2024:8688 released updated OpenShift 4.13.53 images and packages, including fixes for CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158.
RHSA-2024:8428 released OpenShift Container Platform 4.15.37 packages fixing all three Go stack-exhaustion CVEs. Separately, RHSA-2024:8337 updated Run Once Duration Override Operator to 1.1.2 and fixed CVE-2024-34155 and CVE-2024-34158.
RHSA-2024:8260 and RHSA-2024:8263 released OpenShift Container Platform 4.16.18 container images and packages. They addressed the three Go stack-exhaustion flaws, with the image release also covering additional net/http, jose-go, and containers/image issues.
RHSA-2024:8229 and RHSA-2024:8232 released OpenShift Container Platform 4.17.2 images and packages. The update fixed CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158 across supported RHEL 8 and 9 architectures.
Red Hat issued RHSA-2024:8014 for Network Observability 1.7.0 on RHEL 9 and RHSA-2024:8329 for Cryostat 3 on RHEL 8. Both updates fixed the three Go stack-exhaustion denial-of-service vulnerabilities.
RHSA-2024:8112 supplied Buildah 1.33.9-1.el9_4 for RHEL 9, remediating CVE-2024-34155, CVE-2024-34156, CVE-2024-34158, and the containers/common CVE-2024-9341 issue.
RHSA-2024:8039 provided Podman 4.9.4-13.el9_4 for supported RHEL 9 variants, fixing the three Go stack-exhaustion vulnerabilities and CVE-2024-9341 in containers/common.
RHSA-2024:8038 updated the RHEL 8 container-tools module, including Podman, Buildah, Skopeo, and runc, to address CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158.
RHSA-2024:3718 delivered updated OpenShift Container Platform 4.17.0 container images for RHEL 8 and 9 architectures. The Moderate-severity update remediated nine vulnerabilities affecting HashiCorp Vault, SSH, containers/image, Go, Helm, and jose-go, including CVE-2024-24786 and CVE-2024-25620.
Red Hat issued Important advisory RHSA-2024:7262 for osbuild-composer 101-2.el8_10 on RHEL 8, including RHEL 8.10 Extended Life Cycle releases. The update remediated the golang-fips/openssl RSA memory-leak flaw CVE-2024-1394 and the Go encoding/gob stack-exhaustion denial-of-service flaw CVE-2024-34156.
Red Hat issued Moderate advisory RHSA-2024:6969 for the RHEL 8 container-tools:rhel8 module, updating Podman, Buildah, Skopeo, and runc. The update fixed five Go flaws, including multipart-form memory exhaustion, certificate-verification panic, malformed-DNS infinite loop, and HTTP 100-continue denial of service.
RHSA-2024:6912 updated the go-toolset:rhel8 module for RHEL 8.8 extended-support offerings with Go Toolset 1.19.13 packages. The Moderate-severity advisory remediated the net/http HTTP 100-continue denial-of-service flaw CVE-2024-24791 and the encoding/gob stack-exhaustion panic CVE-2024-34156.
RHSA-2024:6913 supplied Go 1.21.13-3.el9_4 packages for RHEL 9, remediating the three Go stack-exhaustion CVEs and the net/http CVE-2024-24791 denial-of-service issue.
RHSA-2024:6908 updated the RHEL 8 go-toolset with Go 1.21.13 packages fixing CVE-2024-34155, CVE-2024-34156, and CVE-2024-34158, along with CVE-2024-24791.
Red Hat issued Important advisory RHSA-2024:6914 for RHEL 9.2 lifecycle and update-support channels, providing golang-1.19.13-12.el9_2 packages. The update remediated the net/http HTTP 100-continue denial-of-service flaw CVE-2024-24791 and the encoding/gob stack-exhaustion panic CVE-2024-34156.
Red Hat reported Bug 2310528 for CVE-2024-34156, a high-severity denial-of-service flaw in Go encoding/gob where Decoder.Decode can panic from stack exhaustion on deeply nested structures.
Red Hat issued Important advisory RHSA-2024:4699 for OpenShift Container Platform 4.15.23, providing updated container images for RHEL 8 and 9 architectures. The release fixed denial-of-service flaws in Go HTTP/2 and dnspython, RSA memory leaks in golang-fips/openssl, and potential sensitive-URL logging by go-retryablehttp.
Red Hat issued Moderate advisory RHSA-2024:3617 for Kube Descheduler Operator 5.0.1 on RHEL 9. The update fixed five Go and golang-protobuf flaws, including memory exhaustion, certificate-verification panic, mail parsing, HTML template escaping, and protojson infinite-loop issues.
Red Hat issued Important advisory RHSA-2024:1616 for Run Once Duration Override Operator 1.1.1 on RHEL 9 x86_64. The update remediated denial-of-service and other flaws in Go and golang-protobuf, including memory exhaustion, HTTP/2 CONTINUATION-frame exhaustion, a certificate-verification panic, and a protojson infinite loop.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
41 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcedocs.openshift.com
Open sourcedocs.openshift.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.