Skip to main content
EPSS 1.0%top 39%

Red Hat Security Advisory: containernetworking-plugins security update

0
Medium
Published: 11/12/2024 (11/12/2024, 09:10:13 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): * golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788) * net/http: Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.

Affected software

Affected versions
>=9.0.0 <9.5.1Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)srccontainernetworking-plugins-1:1.5.1-2.el9.src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:21:23 UTC

Technical Analysis

The Container Network Interface (CNI) project provides specifications and libraries for configuring network interfaces in Linux containers. Two security vulnerabilities have been addressed in the containernetworking-plugins package for Red Hat Enterprise Linux 9: CVE-2024-24788 involves the golang net package where a malformed DNS message can cause an infinite loop, and CVE-2024-24791 involves a denial of service vulnerability in net/http due to improper handling of the HTTP 100-continue mechanism. These vulnerabilities could impact container network connectivity and stability. Red Hat has released updated containernetworking-plugins packages for affected versions to remediate these issues.

Potential Impact

The vulnerabilities can cause denial of service conditions: CVE-2024-24788 may cause an infinite loop in DNS message processing, potentially affecting container network operations, while CVE-2024-24791 can lead to denial of service via improper HTTP 100-continue handling. The overall security impact is rated as moderate by Red Hat. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released updated containernetworking-plugins packages for Red Hat Enterprise Linux 9 versions prior to 9.5.1. Users should apply these official updates to remediate the vulnerabilities. For detailed update instructions, refer to the Red Hat advisory RHSA-2024:9089 and the linked article https://access.redhat.com/articles/11258. No additional mitigation actions are specified or required beyond applying the update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:9089
Cve Count
2
Additional Cves
["CVE-2024-24791"]

Threat ID: 6a1df669e29bf47b50461dc6

Added to database: 06/01/2026, 21:15:21 UTC

Last enriched: 08/14/2026, 23:21:23 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 83

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses