Red Hat released fixes for CVE-2024-3727, a flaw in the widely used github.com/opencontainers/go-digest library in which digest values may not be correctly validated. The weakness can allow unexpected authenticated access to container registries using a victim’s credentials, resource exhaustion, local path traversal, and potentially additional attacks. Red Hat tracked the issue across container-related packages and issued updates for affected OpenShift, Enterprise Linux, Advanced Cluster Security, and related offerings.
The remediation was included in OpenShift Container Platform updates 4.14.34, 4.15.24, 4.16.14, and 4.16.15, as well as Migration Toolkit for Containers 1.8.4. Affected organizations should upgrade clusters and MTC deployments through their supported release channels, using the OpenShift CLI or web console where applicable; the OpenShift updates are available across supported x86_64, s390x, ppc64le, and aarch64 environments.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:9960 for OpenShift API for Data Protection (OADP) 1.3 on RHEL 9, fixing CVE-2024-3727 in the oadp-velero-plugin-rhel9 component.
Red Hat issued Moderate-severity advisory RHSA-2024:9098 for Skopeo on RHEL 9. The Skopeo 1.16.1-1.el9 update remediated CVE-2024-3727 along with Go DNS-loop, sensitive URL logging, and HTTP 100-continue denial-of-service vulnerabilities.
Red Hat issued Moderate-severity advisory RHSA-2024:9097 for Buildah on Red Hat Enterprise Linux 9. Buildah version 1.37.2-1.el9 remediated CVE-2024-3727 in containers/image and CVE-2024-24791, a Go net/http denial-of-service issue.
Red Hat issued Important advisory RHSA-2024:7941 for OpenShift Container Platform 4.13.52. The update remediated CVE-2024-3727 in containers/image, CVE-2024-44082 in openstack-ironic, and CVE-2024-42353 in WebOb.
Red Hat issued Moderate-severity advisory RHSA-2024:7187, releasing OpenShift Container Platform 4.14.38 with updated RPM packages. The update remediated CVE-2024-3727 in containers/image and CVE-2024-42353, an open-redirect vulnerability in WebOb.
Red Hat issued Moderate-severity advisory RHSA-2024:7182 for OpenShift Container Platform 4.15.35. The package update remediated CVE-2024-3727 in containers/image and CVE-2024-42353, an open-redirect issue in WebOb.
Red Hat issued Important advisory RHSA-2024:7174 for OpenShift Container Platform 4.16.15. Updated images and packages addressed CVE-2024-3727 as well as issues in openstack-ironic and Go components.
Red Hat issued Important advisory RHSA-2024:7164, providing Migration Toolkit for Containers 1.8.4 for Red Hat Migration Toolkit 1 on RHEL 8 x86_64. The release fixed CVE-2024-3727 and multiple other bundled-component vulnerabilities.
Red Hat issued Moderate-severity advisory RHSA-2024:6824 for OpenShift Container Platform 4.16.14. The update fixed CVE-2024-3727 alongside vulnerabilities in golang-protobuf, the Bare Metal Operator, and QEMU.
Red Hat issued Important advisory RHSA-2024:6054 for Red Hat Advanced Cluster Security 4.4.5. Updated RHACS images fixed CVE-2024-3727 in containers/image, CVE-2024-37298 in gorilla/schema, and CVE-2024-6104 in go-retryablehttp.
Red Hat issued RHSA-2024:4960, an Important advisory delivering OpenShift Container Platform 4.14.34 updates and container images. The release remediated CVE-2024-3727, whose containers/image digest type did not guarantee a valid type.
Avinash Hanwate reported GO-2024-2824/CVE-2024-24788, in which a malformed DNS response can cause Go DNS Lookup functions to loop indefinitely and create a denial-of-service condition. The issue was tracked as Go project issue 66754, with remediation change 578375.
Red Hat addressed CVE-2024-37298, a gorilla/schema sparse-slice deserialization flaw that can cause excessive memory allocation through schema.Decoder.Decode(), across multiple RHEL and OpenShift releases as well as RHACS. The upstream fix is included in gorilla/schema version 1.4.1.
Red Hat released Moderate-severity OpenShift Container Platform 4.15.24 updates and container images. The release fixed CVE-2024-3727 in containers/image and CVE-2024-0874 in CoreDNS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
17 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.