CVE Vulnerabilities

CVE-2024-24790

Published: Jun 05, 2024 | Modified: Jun 18, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.7 MODERATE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Affected Software

Name Vendor Start Version End Version
Go Golang * 1.21.11 (excluding)
Go Golang 1.22.0 (including) 1.22.4 (excluding)
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-db-rhel8:3.0.0-7 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-grafana-dashboard-rhel8:3.0.0-6 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-operator-bundle:3.0.0-6 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8:3.0.0-7 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-reports-rhel8:3.0.0-6 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-rhel8:3.0.0-6 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-rhel8-operator:3.0.0-6 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/cryostat-storage-rhel8:3.0.0-7 *
Cryostat 3 on RHEL 8 RedHat cryostat-tech-preview/jfr-datasource-rhel8:3.0.0-6 *
OADP-1.3-RHEL-9 RedHat oadp/oadp-velero-rhel9:1.3.3-8 *
Red Hat Enterprise Linux 7 Extended Lifecycle Support RedHat rhc-worker-script-0:0.9-5.el7_9 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8100020240613152020.a3795dee *
Red Hat Enterprise Linux 9 RedHat golang-0:1.21.11-1.el9_4 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/egress-router-cni-rhel9:v4.16.0-202407180206.p0.g7089efe.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/network-tools-rhel9:v4.16.0-202407150636.p0.g39eca10.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-agent-installer-api-server-rhel9:v4.16.0-202407181636.p0.g6b26a25.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-agent-installer-csr-approver-rhel9:v4.16.0-202407111006.p0.g373c87a.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-agent-installer-node-agent-rhel9:v4.16.0-202407180936.p0.g9ca7b58.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-agent-installer-utils-rhel9:v4.16.0-202407181636.p0.g6e6bb40.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-baremetal-installer-rhel9:v4.16.0-202407161206.p0.g41969e2.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-baremetal-rhel9-operator:v4.16.0-202407101906.p0.gf7a6e7f.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cli-artifacts-rhel9:v4.16.0-202407111006.p0.gfa84651.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cli-rhel9:v4.16.0-202407111006.p0.gfa84651.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cloud-credential-rhel9-operator:v4.16.0-202407142206.p0.gfffc75d.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cluster-ingress-rhel9-operator:v4.16.0-202407121806.p0.gaf5d3f6.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cluster-kube-apiserver-rhel9-operator:v4.16.0-202407101906.p0.g0afad8a.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cluster-monitoring-rhel9-operator:v4.16.0-202407121106.p0.gcb3d884.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cluster-network-rhel9-operator:v4.16.0-202407101706.p0.gdc0ef57.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cluster-node-tuning-rhel9-operator:v4.16.0-202407150636.p0.g2bd8891.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-cluster-version-rhel9-operator:v4.16.0-202407111837.p0.g49b0f18.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-console-rhel9:v4.16.0-202407181806.p0.g897c0f7.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-console-rhel9-operator:v4.16.0-202407111306.p0.g595d9d4.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-docker-builder-rhel9:v4.16.0-202407150135.p0.g3b7a1b1.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-hypershift-rhel9:v4.16.0-202407181636.p0.g5a87f94.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-ibm-vpc-block-csi-driver-rhel9:v4.16.0-202407101507.p0.g9571973.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator:v4.16.0-202407110607.p0.g72d41aa.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-installer-altinfra-rhel9:v4.16.0-202407161206.p0.g41969e2.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-installer-artifacts-rhel9:v4.16.0-202407161505.p0.g41969e2.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-installer-rhel9:v4.16.0-202407161505.p0.g41969e2.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-ironic-machine-os-downloader-rhel9:v4.16.0-202407150135.p0.g93b8b5f.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-machine-config-rhel9-operator:v4.16.0-202407101706.p0.gd70a17f.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-must-gather-rhel9:v4.16.0-202407111006.p0.gaea114c.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-openshift-controller-manager-rhel9:v4.16.0-202407161940.p0.gf0536ca.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-operator-lifecycle-manager-rhel9:v4.16.0-202407171536.p0.g1551101.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-operator-registry-rhel9:v4.16.0-202407171536.p0.g1551101.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-ovn-kubernetes-rhel9:v4.16.0-202407111006.p0.g7f41283.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-prometheus-rhel9:v4.16.0-202407160436.p0.g54b1197.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-sdn-rhel9:v4.16.0-202407111006.p0.g5b658c4.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-tests-rhel9:v4.16.0-202407151406.p0.gac6867d.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-tools-rhel9:v4.16.0-202407150636.p0.gfa84651.assembly.stream.el9 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/cluster-logging-operator-bundle:v5.6.21-19 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/cluster-logging-rhel8-operator:v5.6.21-8 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/elasticsearch6-rhel8:v6.8.1-429 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/elasticsearch-operator-bundle:v5.6.21-19 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/elasticsearch-proxy-rhel8:v1.0.0-503 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/elasticsearch-rhel8-operator:v5.6.21-7 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/eventrouter-rhel8:v0.4.0-277 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/fluentd-rhel8:v1.14.6-225 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/kibana6-rhel8:v6.8.1-450 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/log-file-metric-exporter-rhel8:v1.1.0-258 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/logging-curator5-rhel8:v5.8.1-503 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/logging-loki-rhel8:v3.1.0-7 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/logging-view-plugin-rhel8:v5.6.21-3 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/loki-operator-bundle:v5.6.21-33 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/loki-rhel8-operator:v5.6.21-14 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/lokistack-gateway-rhel8:v0.1.0-610 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/opa-openshift-rhel8:v0.1.0-267 *
RHOL-5.6-RHEL-8 RedHat openshift-logging/vector-rhel8:v0.21.0-133 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/cluster-logging-operator-bundle:v5.8.9-22 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/cluster-logging-rhel9-operator:v5.8.9-9 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch6-rhel9:v6.8.1-428 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch-operator-bundle:v5.8.9-18 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-501 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch-rhel9-operator:v5.8.9-6 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-275 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/fluentd-rhel9:v5.8.9-2 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-256 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/logging-curator5-rhel9:v5.8.1-501 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/logging-loki-rhel9:v3.1.0-3 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/logging-view-plugin-rhel9:v5.8.9-4 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/loki-operator-bundle:v5.8.9-28 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/loki-rhel9-operator:v5.8.9-13 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/lokistack-gateway-rhel9:v0.1.0-604 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/opa-openshift-rhel9:v0.1.0-262 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/vector-rhel9:v0.28.1-69 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/cluster-logging-operator-bundle:v5.9.4-27 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/cluster-logging-rhel9-operator:v5.9.4-13 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-274 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/fluentd-rhel9:v5.9.4-4 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-255 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/logging-loki-rhel9:v3.1.0-2 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/logging-view-plugin-rhel9:v5.9.4-4 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/loki-operator-bundle:v5.9.4-34 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/loki-rhel9-operator:v5.9.4-15 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/lokistack-gateway-rhel9:v0.1.0-612 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/opa-openshift-rhel9:v0.1.0-261 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/vector-rhel9:v0.34.1-12 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/client-kn-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-controller-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-istio-controller-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-controller-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-post-install-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-receiver-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-webhook-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-filter-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-ingress-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtchannel-broker-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtping-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-storage-version-migration-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-webhook-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/func-utils-rhel8:1.33.1-1 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/ingress-rhel8-operator:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/knative-rhel8-operator:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/kn-cli-artifacts-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/kourier-control-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/net-istio-controller-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/net-istio-webhook-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serverless-operator-bundle:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serverless-rhel8-operator:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-activator-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-hpa-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-controller-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-queue-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-storage-version-migration-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-webhook-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/svls-must-gather-rhel8:1.33.1-1 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1-tech-preview/backstage-plugins-eventmesh-rhel8:1.33.1-1 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8:1.12.0-6 *
Golang-1.20 Ubuntu mantic *
Golang-1.21 Ubuntu focal *
Golang-1.21 Ubuntu jammy *
Golang-1.21 Ubuntu mantic *
Golang-1.21 Ubuntu noble *
Golang-1.21 Ubuntu upstream *
Golang-1.22 Ubuntu jammy *
Golang-1.22 Ubuntu mantic *
Golang-1.22 Ubuntu noble *
Golang-1.22 Ubuntu upstream *

References