containernetworking-plugins-1.4.0-4.el9_4
エラータID: AXSA:2024-8599:03
The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.
Security Fix(es):
* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2024-1394
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return parameters to free pkey and ctx if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey and ctx will be nil inside the deferred function that should free them.
Update packages.
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return parameters to free pkey and ctx if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey and ctx will be nil inside the deferred function that should free them.
N/A
SRPMS
- containernetworking-plugins-1.4.0-4.el9_4.src.rpm
MD5: e38b4195d7d9c3153786304abf8387c3
SHA-256: f6babe434bc5f51b406a2235868b96e52d828231ed68d19a997f1ba5cc40a8dd
Size: 3.62 MB
Asianux Server 9 for x86_64
- containernetworking-plugins-1.4.0-4.el9_4.x86_64.rpm
MD5: 84fee9b7b7a7a9e2f0c8aa8aee6273ac
SHA-256: 190daf84bf50e3f18834753318ef10b7ccd005b04e98ca4ed7051a4d5630b991
Size: 9.31 MB