目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-1394— Google Golang 安全漏洞

一分钟漏洞结论

影响对象
Red Hat Red Hat Ansible Automation Platform 2.4 for RHEL 8
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Google Golang是美国谷歌(Google)公司的一种静态强类型、编译型语言。Go的语法接近C语言,但对于变量的声明有所不同。Go支持垃圾回收功能。Go的并行模型是以东尼·霍尔的通信顺序进程(CSP)为基础,采取类似模型的其他语言包括Occam和Limbo,但它也具有Pi运算的特征,比如通道传输。在1.8版本中开放插件(Plugin)的支持,这意味着现在能从Go中动态加载部分函数。 Google Golang 存在安全漏洞,该漏洞源于RSA 加密/解密代码中发现内存泄漏缺陷,这可能会导致资源耗尽。

CVSS 7.5 · High EPSS 1.53% · P72

可能的 ATT&CK 技术 1 AI

T1496 · Resource Hijacking

影响版本矩阵 148

厂商产品 版本范围状态
Red Hat NBDE Tang Server 全部 affected
Red Hat OpenShift Developer Tools and Services 全部 affected
全部 affected
Red Hat OpenShift Pipelines 全部 unaffected
Red Hat OpenShift Serverless 全部 affected
Red Hat Red Hat Ansible Automation Platform 1.2 全部 affected
全部 affected
Red Hat Red Hat Ansible Automation Platform 2.4 for RHEL 8 0:1.4.5-1.el8ap< * unaffected
Red Hat Red Hat Ansible Automation Platform 2.4 for RHEL 9 0:1.4.5-1.el9ap< * unaffected
Red Hat Red Hat Certification for Red Hat Enterprise Linux 8 全部 affected
Red Hat Red Hat Certification Program for Red Hat Enterprise Linux 9 全部 affected
Red Hat Red Hat Developer Tools 0:1.19.13-6.el7_9< * unaffected
Red Hat Red Hat Enterprise Linux 7 全部 unknown
全部 unknown
全部 unknown
全部 unknown
全部 unknown
全部 unknown
Red Hat Red Hat Enterprise Linux 8 8090020240313170136.26eb71ac< * unaffected
0:5.1.1-2.el8_9< * unaffected
0:9.2.10-8.el8_9< * unaffected
0:9.2.10-16.el8_10< * unaffected
8100020240808093819.afee755d< * unaffected
0:101-2.el8_10< * unaffected
全部 unaffected
全部 unaffected
… +8 条更多
Red Hat Red Hat Enterprise Linux 9 0:1.20.12-2.el9_3< * unaffected
0:9.2.10-8.el9_3< * unaffected
0:5.1.1-2.el9_3< * unaffected
0:1.21.9-2.el9_4< * unaffected
0:9.2.10-16.el9_4< * unaffected
0:5.1.1-2.el9_4< * unaffected
2:1.33.7-3.el9_4< * unaffected
4:4.9.4-5.el9_4< * unaffected
… +11 条更多
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 2:4.2.0-4.el9_0< * unaffected
1:1.0.1-6.el9_0< * unaffected
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:1.19.13-7.el9_2< * unaffected
2:4.4.1-20.el9_2< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 全部 unaffected
全部 unaffected
全部 unaffected
全部 unknown
全部 unaffected
全部 unaffected
全部 affected
Red Hat Red Hat OpenShift Container Platform 4.12 1:1.23.4-5.2.rhaos4.12.el8< * unaffected
0:0.16.0-2.2.rhaos4.12.el8< * unaffected
1:1.4.0-1.1.rhaos4.12.el8< * unaffected
0:1.25.3-5.2.rhaos4.12.git44a2cb2.el9< * unaffected
0:1.25.0-2.2.el8< * unaffected
0:2.14.0-5.2.rhaos4.12.el9< * unaffected
0:4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el8< * unaffected
3:4.2.0-7.2.rhaos4.12.el9< * unaffected
… +2 条更多
Red Hat Red Hat OpenShift Container Platform 4.13 1:1.29.1-2.2.rhaos4.13.el8< * unaffected
1:1.4.0-1.1.rhaos4.13.el8< * unaffected
0:1.26.5-11.1.rhaos4.13.git919cc6e.el8< * unaffected
0:1.26.0-4.1.el8< * unaffected
0:2.15.0-7.1.rhaos4.13.el9< * unaffected
0:4.13.0-202404020737.p0.gd192e90.assembly.stream.el8< * unaffected
3:4.4.1-5.2.rhaos4.13.el8< * unaffected
4:1.1.12-1.1.rhaos4.13.el8< * unaffected
… +1 条更多
Red Hat Red Hat OpenShift Container Platform 4.14 0:0.19.0-1.3.rhaos4.14.el8< * unaffected
1:1.4.0-1.2.rhaos4.14.el8< * unaffected
0:1.27.4-6.1.rhaos4.14.gitd09e4c0.el8< * unaffected
0:1.27.0-3.1.el8< * unaffected
0:2.16.2-2.1.rhaos4.14.el9< * unaffected
0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el8< * unaffected
0:4.14.0-202403251040.p0.g607e2dd.assembly.stream.el8< * unaffected
3:4.4.1-11.3.rhaos4.14.el8< * unaffected
… +19 条更多
Red Hat Red Hat OpenShift Container Platform 4.15 1:1.29.1-20.3.rhaos4.15.el8< * unaffected
0:0.20.0-1.1.rhaos4.15.el8< * unaffected
1:1.4.0-1.2.rhaos4.15.el8< * unaffected
0:1.28.4-8.rhaos4.15.git24f50b9.el8< * unaffected
0:1.28.0-3.1.el8< * unaffected
0:2.16.2-2.1.rhaos4.15.el9< * unaffected
0:4.15.0-202403211240.p0.g62c4d45.assembly.stream.el8< * unaffected
0:4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el8< * unaffected
… +5 条更多
Red Hat Red Hat Openshift Container Storage 4 全部 unknown
Red Hat Red Hat OpenShift Dev Spaces 全部 affected
Red Hat Red Hat OpenShift GitOps 全部 affected
Red Hat Red Hat OpenShift on AWS 全部 affected
Red Hat Red Hat OpenShift Virtualization 4 全部 unaffected
Red Hat Red Hat OpenStack Platform 16.1 全部 unknown
全部 affected
全部 unaffected
Red Hat Red Hat OpenStack Platform 16.2 0:3.3.23-16.el8ost< * unaffected
全部 affected
全部 affected
全部 unaffected
Red Hat Red Hat OpenStack Platform 17.1 全部 affected
全部 unaffected
Red Hat Red Hat OpenStack Platform 17.1 for RHEL 8 0:0.2.1-3.el8ost< * unaffected
Red Hat Red Hat OpenStack Platform 17.1 for RHEL 9 0:3.4.26-8.el9ost< * unaffected
0:0.2.1-3.el9ost< * unaffected
Red Hat Red Hat OpenStack Platform 18.0 全部 affected
Red Hat Red Hat Service Interconnect 1 全部 affected
全部 affected
全部 affected
Red Hat Red Hat Software Collections 全部 unaffected
Red Hat Red Hat Storage 3 全部 unknown
Red Hat RHODF-4.16-RHEL-9 v4.16.0-137< * unaffected
v4.16.0-38< * unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-1394 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads
来源: CVE Program / CVE List V5
Vulnerability Description
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
在移除最后引用时对内存的释放不恰当(内存泄露)
来源: CVE Program / CVE List V5
Vulnerability Title
Google Golang 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Google Golang是美国谷歌(Google)公司的一种静态强类型、编译型语言。Go的语法接近C语言,但对于变量的声明有所不同。Go支持垃圾回收功能。Go的并行模型是以东尼·霍尔的通信顺序进程(CSP)为基础,采取类似模型的其他语言包括Occam和Limbo,但它也具有Pi运算的特征,比如通道传输。在1.8版本中开放插件(Plugin)的支持,这意味着现在能从Go中动态加载部分函数。 Google Golang 存在安全漏洞,该漏洞源于RSA 加密/解密代码中发现内存泄漏缺陷,这可能会导致资源耗尽。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Red Hat Red Hat Ansible Automation Platform 2.4 for RHEL 8 0:1.4.5-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.4::el8
Red Hat Red Hat Ansible Automation Platform 2.4 for RHEL 9 0:1.4.5-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.4::el8
Red Hat Red Hat Developer Tools 0:1.19.13-6.el7_9 ~ * cpe:/a:redhat:devtools:2023::el7
Red Hat Red Hat Enterprise Linux 8 8090020240313170136.26eb71ac ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:5.1.1-2.el8_9 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:9.2.10-8.el8_9 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:9.2.10-16.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 8100020240808093819.afee755d ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:101-2.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 9 0:1.20.12-2.el9_3 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:9.2.10-8.el9_3 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:5.1.1-2.el9_3 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:1.21.9-2.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:9.2.10-16.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:5.1.1-2.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 2:1.33.7-3.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 4:4.9.4-5.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 6:0.7.3-4.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 2:1.14.3-3.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 1:1.4.0-4.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 4:1.1.12-3.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:132-1.el9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 2:4.2.0-4.el9_0 ~ * cpe:/a:redhat:rhel_e4s:9.0::appstream
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 1:1.0.1-6.el9_0 ~ * cpe:/a:redhat:rhel_e4s:9.0::appstream
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:1.19.13-7.el9_2 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 2:4.4.1-20.el9_2 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red Hat Red Hat OpenShift Container Platform 4.12 1:1.23.4-5.2.rhaos4.12.el8 ~ * cpe:/a:redhat:openshift:4.12::el8
Red Hat Red Hat OpenShift Container Platform 4.12 0:0.16.0-2.2.rhaos4.12.el8 ~ * cpe:/a:redhat:openshift:4.12::el8
Red Hat Red Hat OpenShift Container Platform 4.12 1:1.4.0-1.1.rhaos4.12.el8 ~ * cpe:/a:redhat:openshift:4.12::el8
Red Hat Red Hat OpenShift Container Platform 4.12 0:1.25.3-5.2.rhaos4.12.git44a2cb2.el9 ~ * cpe:/a:redhat:openshift:4.12::el8

二、漏洞 CVE-2024-1394 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级
Qwen3.6-35B-A3B · 6013 chars
Pro+ 专属包含:
漏洞复现靶场录像(真实沙箱构建 + 触发,独家)
漏洞原理深度分析
触发条件与影响面
完整可执行 POC 代码
利用链与缓解建议
POC 打包下载
每月 100+ 条 AI 生成额度

三、漏洞 CVE-2024-1394 的情报信息

登录查看更多情报信息。

CVE-2024-1394 补丁与修复 (2)

CVE-2024-1394 厂商安全公告 (39)

CVE-2024-1394 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-1394

暂无评论


发表评论