CVE-2024-1394: Red Hat Nbde Tang Server

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.

Affected products

  • Red Hat Nbde Tang Server
  • Red Hat Openshift Developer Tools And Services
  • Red Hat Openshift Pipelines
  • Red Hat Openshift Serverless
  • Red Hat Red Hat Ansible Automation Platform 1.2
  • Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 8: before 0:1.4.5-1.el8ap (fixed in 0:1.4.5-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 9: before 0:1.4.5-1.el9ap (fixed in 0:1.4.5-1.el9ap)
  • Red Hat Red Hat Certification For Red Hat Enterprise Linux 8
  • Red Hat Red Hat Certification Program For Red Hat Enterprise Linux 9
  • Red Hat Red Hat Developer Tools: before 0:1.19.13-6.el7_9 (fixed in 0:1.19.13-6.el7_9)
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 8090020240313170136.26eb71ac (fixed in 8090020240313170136.26eb71ac); before 0:5.1.1-2.el8_9 (fixed in 0:5.1.1-2.el8_9); before 0:9.2.10-8.el8_9 (fixed in 0:9.2.10-8.el8_9); before 0:9.2.10-16.el8_10 (fixed in 0:9.2.10-16.el8_10); before 8100020240808093819.afee755d (fixed in 8100020240808093819.afee755d); before 0:101-2.el8_10 (fixed in 0:101-2.el8_10)
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.20.12-2.el9_3 (fixed in 0:1.20.12-2.el9_3); before 0:9.2.10-8.el9_3 (fixed in 0:9.2.10-8.el9_3); before 0:5.1.1-2.el9_3 (fixed in 0:5.1.1-2.el9_3); before 0:1.21.9-2.el9_4 (fixed in 0:1.21.9-2.el9_4); before 0:9.2.10-16.el9_4 (fixed in 0:9.2.10-16.el9_4); before 0:5.1.1-2.el9_4 (fixed in 0:5.1.1-2.el9_4); …
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 2:4.2.0-4.el9_0 (fixed in 2:4.2.0-4.el9_0); before 1:1.0.1-6.el9_0 (fixed in 1:1.0.1-6.el9_0)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:1.19.13-7.el9_2 (fixed in 0:1.19.13-7.el9_2); before 2:4.4.1-20.el9_2 (fixed in 2:4.4.1-20.el9_2)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.12: before 1:1.23.4-5.2.rhaos4.12.el8 (fixed in 1:1.23.4-5.2.rhaos4.12.el8); before 0:0.16.0-2.2.rhaos4.12.el8 (fixed in 0:0.16.0-2.2.rhaos4.12.el8); before 1:1.4.0-1.1.rhaos4.12.el8 (fixed in 1:1.4.0-1.1.rhaos4.12.el8); before 0:1.25.3-5.2.rhaos4.12.git44a2cb2.el9 (fixed in 0:1.25.3-5.2.rhaos4.12.git44a2cb2.el9); before 0:1.25.0-2.2.el8 (fixed in 0:1.25.0-2.2.el8); before 0:2.14.0-5.2.rhaos4.12.el9 (fixed in 0:2.14.0-5.2.rhaos4.12.el9); …
  • Red Hat Red Hat Openshift Container Platform 4.13: before 1:1.29.1-2.2.rhaos4.13.el8 (fixed in 1:1.29.1-2.2.rhaos4.13.el8); before 1:1.4.0-1.1.rhaos4.13.el8 (fixed in 1:1.4.0-1.1.rhaos4.13.el8); before 0:1.26.5-11.1.rhaos4.13.git919cc6e.el8 (fixed in 0:1.26.5-11.1.rhaos4.13.git919cc6e.el8); before 0:1.26.0-4.1.el8 (fixed in 0:1.26.0-4.1.el8); before 0:2.15.0-7.1.rhaos4.13.el9 (fixed in 0:2.15.0-7.1.rhaos4.13.el9); before 0:4.13.0-202404020737.p0.gd192e90.assembly.stream.el8 (fixed in 0:4.13.0-202404020737.p0.gd192e90.assembly.stream.el8); …
  • Red Hat Red Hat Openshift Container Platform 4.14: before 0:0.19.0-1.3.rhaos4.14.el8 (fixed in 0:0.19.0-1.3.rhaos4.14.el8); before 1:1.4.0-1.2.rhaos4.14.el8 (fixed in 1:1.4.0-1.2.rhaos4.14.el8); before 0:1.27.4-6.1.rhaos4.14.gitd09e4c0.el8 (fixed in 0:1.27.4-6.1.rhaos4.14.gitd09e4c0.el8); before 0:1.27.0-3.1.el8 (fixed in 0:1.27.0-3.1.el8); before 0:2.16.2-2.1.rhaos4.14.el9 (fixed in 0:2.16.2-2.1.rhaos4.14.el9); before 0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el8 (fixed in 0:4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el8); …
  • Red Hat Red Hat Openshift Container Platform 4.15: before 1:1.29.1-20.3.rhaos4.15.el8 (fixed in 1:1.29.1-20.3.rhaos4.15.el8); before 0:0.20.0-1.1.rhaos4.15.el8 (fixed in 0:0.20.0-1.1.rhaos4.15.el8); before 1:1.4.0-1.2.rhaos4.15.el8 (fixed in 1:1.4.0-1.2.rhaos4.15.el8); before 0:1.28.4-8.rhaos4.15.git24f50b9.el8 (fixed in 0:1.28.4-8.rhaos4.15.git24f50b9.el8); before 0:1.28.0-3.1.el8 (fixed in 0:1.28.0-3.1.el8); before 0:2.16.2-2.1.rhaos4.15.el9 (fixed in 0:2.16.2-2.1.rhaos4.15.el9); …
  • Red Hat Red Hat Openshift Container Storage 4
  • Red Hat Red Hat Openshift Dev Spaces
  • Red Hat Red Hat Openshift Gitops
  • Red Hat Red Hat Openshift On Aws
  • Red Hat Red Hat Openshift Virtualization 4
  • and 10 more

Published 2024-03-21. Last modified 2026-10-09.