Description

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

INFO

Published Date :

2024-09-06T20:42:42.661Z

Last Modified :

2024-09-26T15:03:08.203Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2024-34156 vulnerability.

Vendors Products
Go Standard Library
  • Encoding\/gob
Redhat
  • Advanced Cluster Security
  • Ceph Storage
  • Cryostat
  • Enterprise Linux
  • Logging
  • Network Observ Optr
  • Openshift
  • Openshift Api Data Protection
  • Openshift Custom Metrics Autoscaler
  • Openshift Devspaces
  • Openstack
  • Openstack Podified
  • Rhel Aus
  • Rhel E4s
  • Rhel Eus
  • Rhel Tus
  • Rhmt
  • Service Interconnect

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact