Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-9355— Golang-fips: golang fips zeroed buffer

Quick assessment

Affected
CVE-2024-9355
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Google Golang是美国谷歌(Google)公司的一种静态强类型、编译型语言。Go的语法接近C语言,但对于变量的声明有所不同。Go支持垃圾回收功能。Go的并行模型是以东尼·霍尔的通信顺序进程(CSP)为基础,采取类似模型的其他语言包括Occam和Limbo,但它也具有Pi运算的特征,比如通道传输。在1.8版本中开放插件(Plugin)的支持,这意味着现在能从Go中动态加载部分函数。 Google Golang存在安全漏洞,该漏洞源于允许恶意用户在FIPS模式下随机导致未初始化的缓冲区长度变量与零缓

CVSS 6.5 · Medium EPSS 0.30% · P21

Possible ATT&CK Techniques 1 AI

T1552.003 · Shell History

Affected Version Matrix 129

VendorProduct Version RangeStatus
None None any affected
Red Hat NBDE Tang Server any affected
Red Hat OpenShift Developer Tools and Services any affected
any affected
Red Hat OpenShift Pipelines any affected
Red Hat OpenShift Serverless any affected
Red Hat Red Hat Ansible Automation Platform 1.2 any affected
any affected
Red Hat Red Hat Ansible Automation Platform 2 any unaffected
any affected
Red Hat Red Hat Enterprise Linux 10 any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
… +10 more rows
Red Hat Red Hat Enterprise Linux 7 any unaffected
any affected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:0.10-2.el7_9< * unaffected
Red Hat Red Hat Enterprise Linux 8 8100020241001112709.a3795dee< * unaffected
0:9.2.10-20.el8_10< * unaffected
0:5.1.1-9.el8_10< * unaffected
0:101.5-2.el8_10< * unaffected
any affected
any unaffected
any affected
any affected
… +7 more rows
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:46.3-8.el8_6< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:46.3-8.el8_6< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:75-10.el8_8< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:75-10.el8_8< * unaffected
Red Hat Red Hat Enterprise Linux 9 0:1.21.13-4.el9_4< * unaffected
0:9.2.10-19.el9_4< * unaffected
0:132-1.el9< * unaffected
0:3.6.1-1.el9< * unaffected
any affected
any affected
any unaffected
any affected
… +10 more rows
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:0.17.0-1.el9_2.1< * unaffected
Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support 0:5.1.1-4.el9_4< * unaffected
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:0.23.0-1.el9_6.1< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
any unaffected
any unaffected
any affected
any unaffected
any unaffected
any unaffected
… +21 more rows
Red Hat Red Hat Openshift Container Storage 4 any affected
Red Hat Red Hat Openshift Data Foundation 4 any unaffected
Red Hat Red Hat OpenShift Dev Spaces any unaffected
Red Hat Red Hat OpenShift GitOps any affected
Red Hat Red Hat OpenShift on AWS any affected
Red Hat Red Hat OpenShift Virtualization 4 any affected
Red Hat Red Hat OpenStack Platform 16.2 any unaffected
any unaffected
any unaffected
any unaffected
Red Hat Red Hat OpenStack Platform 17.1 any unaffected
any unaffected
any unaffected
any unaffected
Red Hat Red Hat Satellite 6 any unaffected
any unaffected
any affected
any affected
any affected
any affected
Red Hat Red Hat Service Interconnect 1 any affected
any unaffected
any affected
Red Hat Red Hat Storage 3 any affected
Red Hat Red Hat Trusted Artifact Signer 1.3 1787305413< * unaffected
Red Hat Satellite Client 6 for RHEL 10 0:0.3.1-1.el10sat< * unaffected
Red Hat Satellite Client 6 for RHEL 8 0:0.3.1-1.el8sat< * unaffected
Red Hat Satellite Client 6 for RHEL 9 0:0.3.1-1.el9sat< * unaffected
Red Hat Streams for Apache Kafka 2.9.0 any unaffected

I. Basic Information for CVE-2024-9355

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Golang-fips: golang fips zeroed buffer
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用未经初始化的变量
Source: CVE Program / CVE List V5
Vulnerability Title
Google Golang 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Golang是美国谷歌(Google)公司的一种静态强类型、编译型语言。Go的语法接近C语言,但对于变量的声明有所不同。Go支持垃圾回收功能。Go的并行模型是以东尼·霍尔的通信顺序进程(CSP)为基础,采取类似模型的其他语言包括Occam和Limbo,但它也具有Pi运算的特征,比如通道传输。在1.8版本中开放插件(Plugin)的支持,这意味着现在能从Go中动态加载部分函数。 Google Golang存在安全漏洞,该漏洞源于允许恶意用户在FIPS模式下随机导致未初始化的缓冲区长度变量与零缓
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - - -
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:0.10-2.el7_9 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 8100020241001112709.a3795dee ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:9.2.10-20.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:5.1.1-9.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8 0:101.5-2.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:46.3-8.el8_6 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:46.3-8.el8_6 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:75-10.el8_8 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:75-10.el8_8 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 9 0:1.21.13-4.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:9.2.10-19.el9_4 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:132-1.el9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:3.6.1-1.el9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:0.17.0-1.el9_2.1 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support 0:5.1.1-4.el9_4 ~ * cpe:/a:redhat:rhel_eus:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:0.23.0-1.el9_6.1 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Satellite Client 6 for RHEL 10 0:0.3.1-1.el10sat ~ * cpe:/a:redhat:rhel_satellite_client:6::el10
Red Hat Satellite Client 6 for RHEL 8 0:0.3.1-1.el8sat ~ * cpe:/a:redhat:rhel_satellite_client:6::el10
Red Hat Satellite Client 6 for RHEL 9 0:0.3.1-1.el9sat ~ * cpe:/a:redhat:rhel_satellite_client:6::el10
Red Hat Streams for Apache Kafka 2.9.0 - cpe:/a:redhat:amq_streams:2
Red Hat Red Hat Trusted Artifact Signer 1.3 1787305413 ~ * cpe:/a:redhat:trusted_artifact_signer:1.3::el9
Red Hat NBDE Tang Server - cpe:/a:redhat:network_bound_disk_encryption_tang:1
Red Hat OpenShift Developer Tools and Services - cpe:/a:redhat:ocp_tools
Red Hat OpenShift Developer Tools and Services - cpe:/a:redhat:ocp_tools
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1
Red Hat OpenShift Serverless - cpe:/a:redhat:serverless:1
Red Hat Red Hat Ansible Automation Platform 1.2 - cpe:/a:redhat:ansible_automation_platform
Red Hat Red Hat Ansible Automation Platform 1.2 - cpe:/a:redhat:ansible_automation_platform
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2024-9355

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-9355

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-9355 (1)

Vendor Advisories for CVE-2024-9355 (15)

IV. Related Vulnerabilities

V. Comments for CVE-2024-9355

No comments yet


Leave a comment