Skip to main content
EPSS 1.3%top 32%

Red Hat Bug Fix Advisory: LVMS 4.14.10 Bug Fix Update

0
High
Published: 10/16/2024 (10/16/2024, 14:03:37 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform. This advisory contains OpenShift Virtualization 4.14.7 images.

Affected software

Affected versions
>=4.14.0 <=4.14.17Red Hatlogical volume manager storageLVMS 4.15 for RHEL 9amd64lvms4/lvms-must-gather-rhel9@sha256:c15a55a4ff7cf52fb070533b53c53b6d9ebe57eda2d6f794966d4cf8fd76b89a_amd64LVMS 4.14 for RHEL 9ppc64lelvms4/lvms-must-gather-rhel9@sha256:b06a9313e2a8e36400e3a888fb9c61e490f8076a36137b816b06d046e47e2bac_ppc64leOpenShift VirtualizationCNV 4.14 for RHEL 9container-native-virtualization/bridge-marker-rhel9@sha256:f674436335d36d0927c4752498104d6d271e4f0f88eedb5a45da1ed9c71888db_amd64Red Hat OpenShift Serverless8Base-Openshift-Serverless-1.35openshift-serverless-1/logic-data-index-ephemeral-rhel8@sha256:d7e430549b5bb731d2dcdfe035eaad09749a715a20fb317f0a298c2816416993_ppc64leRed Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.14Red Hat OpenShift Container Platform 4.13srcRed Hat OpenShift Container Platform 4.15Red Hat OpenShift Container Platform 4.17arm64openshift4/ose-cluster-etcd-rhel9-operator@sha256:825e4e348b89553e547c57929cd914ae0fa9e315a9866b7bde84346cf263053f_arm64logging for Red Hat OpenShiftRHOL 5.8 for RHEL 9s390xopenshift-logging/cluster-logging-rhel9-operator@sha256:7b9bbf6d009b516d21af7ccf84653a9f1140146952eca1b85484bdbe3690084d_s390xRHOL 5.6 for RHEL 8openshift-logging/cluster-logging-rhel8-operator@sha256:e29388425c629b3cac16c389f296b440ee921d0324ae8ddb26b1a0d03fca07e9_s390xRHOL 5.7 for RHEL 8openshift-logging/cluster-logging-rhel8-operator@sha256:d147ced8dea6ba59102e9e0cd87078d97f4f5e7f9577da8b7739efc447a49b6b_amd64openshift4/cnf-tests-rhel8@sha256:1557755b7221f41738b6b607af8412d6fb541ceb08fd48f82ad5580d8daafc9f_amd64Red Hat OpenShift Container Platform 4.12openshift4/cnf-tests-rhel8@sha256:45ea2c0408804e55d7368805547810532c141ac614a410ed445624814003fd45_amd64Red Hat ACMRed Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9rhacm2/volsync-rhel9@sha256:abd52a1d65ab140fe084a5c2e7983075c6883f90252ccf4c8ff0cab62c0660a3_arm64Red Hat Enterprise LinuxRed Hat Enterprise Linux Client (v. 7)Red Hat Enterprise Linux Server (v. 7)Red Hat Enterprise Linux Workstation (v. 7)Red Hat Enterprise Linux AppStream (v. 9)skopeo-2:1.14.3-2.el9_4.srcbuildah-2:1.33.7-1.el9_4.srcRed Hat Migration Toolkit8Base-RHMTC-1.7rhmtc/openshift-migration-controller-rhel8@sha256:c312ff737af8d68dd54d16478940ec45b263aeafae10692d1b415b67e4ff85dd_amd64openshift4/ose-descheduler@sha256:a3901750738704ce7dbdef2868f1a3f36fbee65981caf5f05b25ecc212318713_ppc64leaarch64Red Hat OpenShift Service MeshRHOSSM 2.5 for RHEL 8openshift-service-mesh/kiali-ossmc-rhel8@sha256:86ef5f79cfb77eb6104b5279b644f1580d2b4c870157793043f8b44ed7144540_ppc64leRed Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.12Red Hat Enterprise Linux AppStream (v. 8)aardvark-dns-2:1.10.0-1.module+el8.10.0+21962+8143777b.src::container-tools:rhel8Red Hat OpenShift GitOps 1.11openshift-gitops-1/argocd-rhel8@sha256:f10e4081655abf6e5c99ad32000fe98f06299cbe55434908d3161d072fde2c20_s390xCNV 4.16 for RHEL 9container-native-virtualization/aaq-controller-rhel9@sha256:042da8264d3600e96d1f4628bfa77f449c10ab28c8d2a73b1b8654a2832d5ac8_amd64Red Hat OpenShift Container Platform 4.16openshift4/ose-cluster-autoscaler-rhel9@sha256:e972dc8908e17bd076ad427b736859b71d8d4630eeabd9d54a7c6467553e4734_s390xopenshift4/azure-kms-encryption-provider-rhel9@sha256:bdeb71038869db8d546b3c3a19f29e8f3dc65f548193dcb189f5446c0d6e51ab_ppc64leKube Descheduler OperatorKDO 5.0 for RHEL 9kube-descheduler-operator/descheduler-rhel9@sha256:8e9112c13e3eda54533a29da7bc20ee4b163ba92fb640b7d8c4faabe49ca73af_ppc64leopenshift4/ose-cluster-node-tuning-rhel9-operator@sha256:df87192e9855071ba67b68957d5ae88cbc2903026b83cacb00d7d48d78375750_s390x<0.89.0-r0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:40:17 UTC

Technical Analysis

A flaw in the golang-protobuf module's protojson.Unmarshal function can cause an infinite loop when unmarshaling certain malformed JSON inputs. This occurs specifically when unmarshaling messages that include google.protobuf.Any or when the UnmarshalOptions.DiscardUnknown option is enabled. An attacker could exploit this by providing crafted invalid JSON input, causing the function to consume excessive CPU or memory resources, resulting in a denial of service condition. Red Hat OpenShift Container Platform 4.14 versions up to 4.14.17 are affected. Red Hat has issued a security advisory (RHSA-2024:1362) with updated container images and packages to fix the vulnerability. The CVSS v3 base score assigned by Red Hat is 5.9 (medium severity), reflecting a network attack vector with high complexity and no privileges or user interaction required. No known exploits are reported in the wild. Mitigation options other than applying the update are not considered practical or effective by Red Hat.

Potential Impact

The vulnerability can cause an infinite loop during JSON unmarshaling in affected golang-protobuf components, leading to high CPU and memory consumption. This results in a denial of service condition, potentially degrading or halting the operation of affected OpenShift Container Platform components. There is no impact on confidentiality or integrity. The attack requires sending specially crafted invalid JSON input to the vulnerable component.

Mitigation Recommendations

Red Hat has released updated packages and container images for OpenShift Container Platform 4.14.17 that fix this vulnerability. Users should apply these updates following Red Hat's official guidance. No other mitigations are currently recommended or available that meet Red Hat's criteria for ease of use and applicability. Ensure all previously released errata relevant to your system have been applied before updating.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:4204
Cve Count
2
Additional Cves
["CVE-2025-30204"]

Threat ID: 6a160956e29bf47b5061baf1

Added to database: 05/26/2026, 20:57:58 UTC

Last enriched: 08/14/2026, 22:40:17 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 93

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2024:1362https://access.redhat.com/security/updates/classification/#moderatehttps://access.redhat.com/security/cve/cve-2024-247862268046Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1363Canonical URLhttps://access.redhat.com/errata/RHSA-2024:14562268854Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1461Canonical URLhttps://access.redhat.com/errata/RHSA-2024:14742269576LOG-5044LOG-5171LOG-5201LOG-5240LOG-5250LOG-5270LOG-5272LOG-5274Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1507LOG-5203LOG-5242LOG-5252LOG-5276Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1508LOG-5172LOG-5202LOG-5241LOG-5251LOG-5275Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1537Canonical URLhttps://access.redhat.com/errata/RHSA-2025:066423014562310908Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1538Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1795ACM-10615Canonical URLhttps://access.redhat.com/errata/RHSA-2024:1874HMS-3843Canonical URLhttps://access.redhat.com/errata/RHSA-2024:2549Canonical URLhttps://access.redhat.com/errata/RHSA-2024:2550Canonical URLhttps://access.redhat.com/errata/RHBA-2024:8188Canonical URLhttps://access.redhat.com/errata/RHBA-2024:8194Canonical URLhttps://access.redhat.com/errata/RHEA-2024:4835CNV-37739CNV-40434CNV-41450CNV-41950CNV-42130CNV-42484CNV-42918CNV-43125CNV-43662CNV-44479Canonical URLhttps://access.redhat.com/errata/RHSA-2024:2639Canonical URLhttps://access.redhat.com/errata/RHSA-2025:4204https://access.redhat.com/security/updates/classification/#important2354195OCPBUGS-43005OCPBUGS-52957OCPBUGS-52999OCPBUGS-53036OCPBUGS-53037OCPBUGS-53077OCPBUGS-54534OCPBUGS-54941OCPBUGS-54960OCPBUGS-55033OCPBUGS-55080OCPBUGS-55224Canonical URLhttps://access.redhat.com/errata/RHSA-2024:2666Canonical URLhttps://access.redhat.com/errata/RHSA-2024:416322643362265440GITOPS-4758Canonical URLhttps://access.redhat.com/errata/RHSA-2024:2781OCPBUGS-32047Canonical URLhttps://access.redhat.com/errata/RHSA-2024:870423105272310529Canonical URLhttps://access.redhat.com/errata/RHSA-2024:2874Canonical URLhttps://access.redhat.com/errata/RHSA-2024:3683OSSM-6290OSSM-6295OSSM-6298OSSM-6299OSSM-6397Canonical URLhttps://access.redhat.com/errata/RHSA-2024:3715Canonical URLhttps://access.redhat.com/errata/RHSA-2024:3717OCPBUGS-30549OCPBUGS-33137OCPBUGS-33594OCPBUGS-33741OCPBUGS-33799OCPBUGS-34045OCPBUGS-34131OCPBUGS-34159OCPBUGS-34190OCPBUGS-34282OCPBUGS-34340OCPBUGS-34344OCPBUGS-35351OCPBUGS-36243OCPBUGS-36268OCPBUGS-36683OCPBUGS-37567https://access.redhat.com/errata/RHSA-2024:4150Canonical URLhttps://access.redhat.com/errata/RHSA-2024:4246Canonical URLhttps://access.redhat.com/errata/RHSA-2024:4626Canonical URLhttps://access.redhat.com/errata/RHSA-2024:50542300499CNV-23540CNV-36845CNV-39739CNV-41081CNV-41538CNV-41948CNV-41962CNV-42128CNV-42157CNV-42223CNV-42365CNV-42482CNV-42508CNV-42700CNV-43206CNV-43209https://access.redhat.com/errata/RHSA-2024:54222292331OCPBUGS-34384OCPBUGS-34690OCPBUGS-34801OCPBUGS-35407OCPBUGS-36171OCPBUGS-36484OCPBUGS-36918OCPBUGS-37060OCPBUGS-37857OCPBUGS-37967OCPBUGS-38015OCPBUGS-38035OCPBUGS-38093OCPBUGS-38129OCPBUGS-38167OCPBUGS-38290https://access.redhat.com/errata/RHSA-2024:8434OCPBUGS-29698OCPBUGS-34277OCPBUGS-34310OCPBUGS-39121OCPBUGS-41621OCPBUGS-41722OCPBUGS-41812OCPBUGS-42108OCPBUGS-42327OCPBUGS-42474OCPBUGS-42638OCPBUGS-42704OCPBUGS-42794OCPBUGS-42876OCPBUGS-42955OCPBUGS-42979OCPBUGS-43088https://access.redhat.com/errata/RHSA-2024:9615OCPBUGS-36290OCPBUGS-38930OCPBUGS-43344OCPBUGS-43834OCPBUGS-43967OCPBUGS-44104OCPBUGS-44105OCPBUGS-44182OCPBUGS-44194OCPBUGS-44234OCPBUGS-44301OCPBUGS-44337OCPBUGS-44351OCPBUGS-44361Canonical URLReference 208Reference 209Reference 210Reference 211Reference 212Reference 213Reference 214Reference 215Reference 216Reference 217Reference 218Reference 219Reference 220Reference 221Reference 222Reference 223Reference 224Reference 225Reference 226Reference 227Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses