CVE-2024-3049: Clusterlabs Booth

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

Affected products

  • Clusterlabs Booth: before 1.1 (fixed in 1.1)
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Eus: version 8.4 only; version 8.8 only; version 9.2 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only; version 8.8_aarch64 only; version 9.2_aarch64 only; version 9.4_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only; version 9.2_s390x only; version 9.4_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.8_s390x only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.0_ppc64le only; version 8.4_ppc64le only; version 8.8_ppc64le only; version 9.2_ppc64le only; version 9.4_ppc64le only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 8.4 only

Published 2024-06-06. Last modified 2026-06-17.