Red Hat issued updates across Red Hat Enterprise Linux, OpenShift, and multiple cloud-native products to remediate CVE-2024-24790 (GO-2024-2887), a Go net/netip flaw in which address-classification methods such as IsPrivate and IsLoopback incorrectly returned false for IPv4 addresses expressed as IPv4-mapped IPv6 addresses. The behavior could cause software that relies on these checks to misapply network access controls or trust decisions. Upstream fixes were delivered in Go 1.22.5 and 1.21.12.
Affected Red Hat releases include OpenShift Container Platform 4.13.48 and 4.15.28, OpenShift API for Data Protection 1.3.3, Cost Management Metrics Operator 3.3.1, and Kube Descheduler Operator 5.1.0, spanning x86_64, ARM64, IBM Power, and IBM Z/LinuxONE environments. RHACS 4.4.6 and 4.5.5 also include the Go fix alongside remediations for body-parser denial of service and other dependency vulnerabilities; Red Hat advises customers to upgrade affected products through their applicable release channels.

See affected versions and whether adversaries are exploiting it.
26 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:10775 for updated RHACS 4.6 container images, remediating CVE-2024-4067, CVE-2024-39249, CVE-2024-24789, and CVE-2024-24790. The advisory applies to RHACS on RHEL 8 across x86_64, s390x, ppc64le, and aarch64 architectures.
RHSA-2024:10186 released Red Hat Advanced Cluster Security 4.5.5, remediating CVE-2024-45590 and CVE-2024-24790 along with Go, DOMPurify, cross-spawn, and RHACS scanner issues.
RHSA-2024:9583 released Red Hat Advanced Cluster Security 4.4.6, fixing CVE-2024-24790 and CVE-2024-45590, plus Go encoding/gob, ZIP handling, and DOMPurify prototype-pollution flaws.
RHSA-2024:9115 updated Grafana for RHEL 9 to version 10.2.6-4.el9, remediating Go DNS, ZIP-handling, HTTP 100-continue, IPv4-mapped IPv6, and URL-logging vulnerabilities including CVE-2024-24790. The update covered supported RHEL 9 architectures and applicable extended-support variants.
Red Hat issued Moderate-severity advisory RHSA-2024:7987 for Red Hat Satellite 6.15 on RHEL 8, providing Satellite 6.15.4. The update remediated CVE-2024-24790 alongside Gunicorn request-smuggling, python-cryptography NULL-pointer dereference, and Django denial-of-service vulnerabilities.
RHSA-2024:5436 released OpenShift Container Platform 4.14.35 RPM packages for RHEL 8 and RHEL 9 architectures. The Moderate-severity update remediated Go vulnerabilities CVE-2023-45290 and CVE-2024-24790.
RHSA-2024:5446 released OpenShift Container Platform 4.13.48 RPM packages for supported RHEL 8 and RHEL 9 architectures. The update remediated CVE-2024-24790, CVE-2023-45290, and the go-retryablehttp URL logging flaw CVE-2024-6104.
Red Hat issued Important advisory RHSA-2024:5547 for OpenShift Data Foundation 4.16.1 on RHEL 9, providing updated container images and a Ceph RHCEPH-7.1z1 upgrade. The update remediated Go DNS parsing CVE-2024-24788, IPv4-mapped IPv6 handling CVE-2024-24790, go-retryablehttp URL logging CVE-2024-6104, and Node.js ws denial of service CVE-2024-37890.
RHSA-2024:5202 released OpenShift Container Platform 4.12.63 RPM packages, remediating CVE-2024-24790, the Go multipart-form memory-exhaustion flaw CVE-2023-45290, and gorilla/schema sparse-slice deserialization flaw CVE-2024-37298.
Red Hat issued RHSA-2024:5258 for the RHEL 8 container-tools module, updating Podman, Buildah, Skopeo, and runc. The Important-severity advisory remediated CVE-2024-24783, CVE-2023-45290, CVE-2024-24784, CVE-2024-24789, CVE-2024-6104, CVE-2024-37298, and other container-stack flaws.
Red Hat issued RHSA-2024:5077 for the go-toolset:rhel8 module on RHEL 8.8. The Moderate-severity update provided Go Toolset and Golang 1.19.13-9 packages that remediate CVE-2023-45290 and the IPv4-mapped IPv6 net/netip flaw CVE-2024-24790.
Red Hat issued RHSA-2024:4785 for Network Observability 1.6.1 for Red Hat OpenShift on RHEL 9. The Moderate-severity update remediated Go archive/zip flaw CVE-2024-24789 and IPv4-mapped IPv6 net/netip flaw CVE-2024-24790.
Red Hat issued RHSA-2024:5075, a Moderate-severity update providing golang-1.19.13-9.el9_2 packages for applicable RHEL 9.2 offerings. The update remediated the Go multipart-form memory-exhaustion flaw CVE-2023-45290 and IPv4-mapped IPv6 net/netip flaw CVE-2024-24790.
Red Hat issued RHSA-2024:4893 for rhc-worker-script on RHEL 7 Extended Life Cycle Support for x86_64. The Moderate-severity update remediated CVE-2024-24790 along with Go multipart-form, crypto/x509 certificate-validation, and html/template escaping flaws.
Red Hat issued Moderate-severity advisory RHSA-2024:4697 for the Red Hat build of Cryostat 3 on RHEL 8. The update supplied updated container images and remediated Go DNS infinite-loop flaw CVE-2024-24788 and IPv4-mapped IPv6 net/netip flaw CVE-2024-24790.
Red Hat issued Moderate-severity advisory RHSA-2024:4212 for RHEL 9, providing golang 1.21.11-1.el9_4 and associated packages. The update remediated Go archive/zip flaw CVE-2024-24789 and IPv4-mapped IPv6 net/netip flaw CVE-2024-24790.
Red Hat issued Moderate-severity advisory RHSA-2024:4237 for Go Toolset on RHEL 8, providing Go Toolset and Golang 1.21.11 packages. The update remediated the Go archive/zip handling flaw CVE-2024-24789 and IPv4-mapped IPv6 net/netip flaw CVE-2024-24790.
Tom Sweeney stated that the fix for CVE-2024-24790/GO-2024-2887 was expected in Go 1.22.5 and Go 1.21.12.
Go documented CVE-2024-24790, in which net/netip classification methods such as IsPrivate and IsLoopback returned false for IPv4-mapped IPv6 addresses whose equivalent IPv4 addresses would return true. The remediation added IPv6-mapped address checks to affected methods on the go1.21 and go1.22 release branches; Enze Wang of Alioth and Jianjun Chen of Zhongguancun Lab reported the issue.
Robb Gatica described a flaw in Go's ParseAddressList function that incorrectly handles parenthesized comments in email display names. The divergent parsing behavior can cause applications using different parsers to make inconsistent trust or security decisions for the same address string.
CVE-2024-24783 was documented as a Go crypto/x509 flaw in which Certificate.Verify can panic on certificate chains containing an unknown public-key algorithm. It affects Go TLS clients and servers configured to verify supplied client certificates, while default Go TLS server configurations are not affected.
RHSA-2024:6341 released Kube Descheduler Operator 5.1.0 for RHEL 9 and fixed CVE-2024-24790 alongside malformed-DNS and HTTP 100-continue Go vulnerabilities.
RHSA-2024:6462 delivered Cost Management Metrics Operator 3.3.1, fixing CVE-2024-24790 and Go flaws that could enable malformed-DNS infinite loops or HTTP 100-continue denial of service.
RHSA-2024:5442 made OpenShift Container Platform 4.15.28 packages available, remediating CVE-2024-24790 and the Go multipart-form memory-exhaustion flaw CVE-2023-45290.
RHSA-2024:5444 delivered OpenShift Container Platform 4.13.48 container images and fixed CVE-2024-24790, as well as Linux kernel, Go multipart-form, logging, and OpenSSH flaws.
RHSA-2024:4982 released OpenShift API for Data Protection 1.3.3, fixing CVE-2024-24790 along with Go HTTP/2, DNS parsing, and ZIP-processing vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
28 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.