Red Hat released Important-severity updates for Red Hat Service Interconnect 1.4 and 1.5, RHEL 9.2 Go packages, and Red Hat OpenStack Platform 17.1 director Operator images to remediate multiple Go vulnerabilities. Key issues include CVE-2023-45288, where unlimited HTTP/2 CONTINUATION frames can exhaust resources; CVE-2024-24783, which can panic crypto/x509 certificate verification when an unknown public-key algorithm is processed; and CVE-2023-39326, in which oversized HTTP chunk extensions can drive server memory consumption to roughly 1 GiB. The OpenStack update also fixes CVE-2023-48795, an SSH Binary Packet Protocol prefix-truncation flaw.
Red Hat additionally updated OpenShift Container Platform 4.13 and 4.14 releases for CVE-2024-1394, a memory leak in golang-fips/openssl RSA encryption and decryption operations; OpenShift 4.14.19 also addresses CVE-2024-28180, involving improper handling of highly compressed data in jose-go. Affected organizations should update Service Interconnect images and skupper-cli, deploy the updated RHEL Go packages and OpenStack operator images, and upgrade OpenShift clusters through their supported release channels across x86_64, ARM64, IBM Power, and IBM Z/LinuxONE where applicable.

See real exploitation activity before you spend the cycle.
19 events from the most recent confirmed update back to the earliest known activity.
RHSA-2024:4146 provided golang-1.19.13-7.el9_2 for affected RHEL 9.2 support channels and architectures. The Important update fixed CVE-2023-45288 and CVE-2024-1394.
Red Hat issued RHSA-2024:4126, an Important update providing Service Interconnect 1.4.5 container images for RHEL 9 x86_64. It addressed CVE-2024-24783, CVE-2023-45288, and additional listed Go vulnerabilities.
RHSA-2024:4125 released Service Interconnect 1.4.5 packages, including skupper-cli for RHEL 8 and RHEL 9 x86_64. The update remediated CVE-2024-24783 and the HTTP/2 CONTINUATION-frame denial-of-service flaw CVE-2023-45288.
Red Hat issued RHSA-2024:4034 for Service Interconnect 1.5.4 OpenShift container images. The Important update fixed Go CVE-2023-45288 and CVE-2024-24783, as well as Service Interconnect issues SKUPPER-1705 and SKUPPER-1812.
Red Hat issued RHSA-2024:3479, an Important update for director Operator container images in Red Hat OpenStack Platform 16.2 (Train) on RHEL 8.4. The update remediated Go-related CVE-2023-39326, CVE-2023-45288, CVE-2023-48795, and goproxy denial-of-service flaw CVE-2023-37788.
RHSA-2024:2728 delivered updated Red Hat OpenStack Platform 17.1 director Operator images for RHEL 9.2, addressing CVE-2023-39326, CVE-2023-45288, and CVE-2023-48795.
Red Hat issued RHSA-2024:3314 for OpenShift Virtualization 4.15.2 images for Red Hat Container Native Virtualization 4.15 on RHEL 9 x86_64. The Important update fixed the Go HTTP/2 CONTINUATION-frame denial-of-service flaw CVE-2023-45288, follow-redirects URL-validation flaw CVE-2023-26159, and axios cookie-data exposure CVE-2023-45857.
Red Hat issued RHSA-2024:2729 for Red Hat OpenStack Platform 17.1 on RHEL 9 x86_64, updating etcd to 3.4.26-8.el9ost. The Important advisory fixed the incomplete etcd HTTP/2 DoS mitigation CVE-2024-4438 and Go-related CVE-2023-39326, CVE-2023-45287, CVE-2023-45288, and CVE-2024-1394.
Red Hat issued RHSA-2024:2941 for Red Hat Advanced Cluster Security 4.4.2, updating Go and golang.org/x/net to address the HTTP/2 CONTINUATION-frame denial-of-service flaw CVE-2023-45288. The Important advisory also fixed webpack-dev-middleware file-disclosure flaw CVE-2024-29180 and multiple RHACS Collector, Scanner, network-graph, and alert-handling issues.
Red Hat issued RHSA-2024:1763, an Important update for OpenShift Container Platform 4.13.40, to remediate CVE-2024-1394 memory leaks during RSA payload encryption and decryption in golang-fips/openssl.
Red Hat issued RHSA-2024:1901 for Red Hat Service Interconnect 1.5.3 OpenShift container images on RHEL 9. The Moderate update remediated multiple Go flaws, including CVE-2023-39318, CVE-2023-39319, CVE-2023-39321, CVE-2023-39322, CVE-2023-45287, and CVE-2023-39326, and fixed Skupper defects including SKUPPER-1304, SKUPPER-1338, SKUPPER-1463, and SKUPPER-976.
Red Hat issued RHSA-2024:1567 for OpenShift Container Platform 4.14.19, fixing CVE-2024-1394 memory leaks in golang-fips/openssl and CVE-2024-28180 improper handling of highly compressed jose-go data.
Red Hat published CVE-2023-45290, a Moderate Go net/http vulnerability where extremely long multipart-form lines could bypass aggregate form-size limits, causing arbitrarily large memory allocations and denial of service. The fix enforces a maximum size for individual multipart form lines in ParseMultipartForm.
Red Hat published CVE-2024-24783, a Moderate Go crypto/x509 flaw in which Certificate.Verify can panic on a certificate chain containing an unknown public-key algorithm. A remote attacker could trigger the fault by supplying a crafted client certificate to affected TLS services configured to verify client certificates.
Patrick Del Bello documented GO-2023-2382, a Go net/http chunked-transfer decoding flaw in which oversized chunk extensions could cause excessive network reads and denial of service.
Robb Gatica disclosed CVE-2023-45857 in Axios 1.5.1, where the XSRF-TOKEN cookie value could be added to the X-XSRF-TOKEN header for requests to any host. An attacker-controlled host could receive the sensitive token if induced to receive such a request.
Red Hat tracked CVE-2023-26159 in follow-redirects versions before 1.15.4, where fallback from the URL() parser to url.parse() could allow hostname misinterpretation and redirects to attacker-controlled sites. Red Hat issued or tracked remediations across RHOL, Migration Toolkit for Applications, Network Observability, OpenShift distributed tracing, OpenShift Container Platform, MCE, and other products.
Red Hat tracked CVE-2023-45287 (GO-2023-2375), affecting Go versions before 1.20 during RSA-based TLS key exchanges. Non-constant-time math/big operations and PKCS#1 padding removal could leak timing information; Go 1.20 introduced a fully constant-time RSA implementation in crypto/tls.
Red Hat issued updates for RHEL 7, 8, and 9 and numerous products containing affected Go components to address GO-2023-2382/CVE-2023-39326. The remediation makes Go's chunked-encoding reader reject inputs with an excessively low ratio of body data to encoded bytes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.