CVE-2024-9355
EUVD-2024-291601.10.2024, 19:15
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| git-lfs |
| ||||
| go-toolset |
| ||||
| golang |
| ||||
| golang-bin |
| ||||
| golang-docs |
| ||||
| golang-misc |
| ||||
| golang-src |
| ||||
| golang-tests |
| ||||
| grafana |
| ||||
| grafana-selinux |
| ||||
| osbuild-composer |
| ||||
| osbuild-composer-core |
| ||||
| osbuild-composer-worker |
|
Common Weakness Enumeration
References