๐Ÿ” CVE Alert

CVE-2024-9355

MEDIUM 6.5

Golang-fips: golang fips zeroed buffer

CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
22th

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.ย  It is also possible to force a derived key to be all zeros instead of an unpredictable value.ย  This may have follow-on implications for the Go TLS stack.

CWE CWE-457
Published Oct 1, 2024
Last Updated Apr 18, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Red Hat / Red Hat Enterprise Linux 7 Extended Lifecycle Support
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9.4 Extended Update Support
All versions affected
Red Hat / Satellite Client 6 for RHEL 10
All versions affected
Red Hat / Satellite Client 6 for RHEL 8
All versions affected
Red Hat / Satellite Client 6 for RHEL 9
All versions affected
Red Hat / Streams for Apache Kafka 2.9.0
All versions affected
Red Hat / NBDE Tang Server
All versions affected
Red Hat / OpenShift Developer Tools and Services
All versions affected
Red Hat / OpenShift Developer Tools and Services
All versions affected
Red Hat / OpenShift Pipelines
All versions affected
Red Hat / OpenShift Serverless
All versions affected
Red Hat / Red Hat Ansible Automation Platform 1.2
All versions affected
Red Hat / Red Hat Ansible Automation Platform 1.2
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat Openshift Container Storage 4
All versions affected
Red Hat / Red Hat Openshift Data Foundation 4
All versions affected
Red Hat / Red Hat OpenShift Dev Spaces
All versions affected
Red Hat / Red Hat OpenShift GitOps
All versions affected
Red Hat / Red Hat OpenShift on AWS
All versions affected
Red Hat / Red Hat OpenShift Virtualization 4
All versions affected
Red Hat / Red Hat OpenStack Platform 16.2
All versions affected
Red Hat / Red Hat OpenStack Platform 16.2
All versions affected
Red Hat / Red Hat OpenStack Platform 16.2
All versions affected
Red Hat / Red Hat OpenStack Platform 16.2
All versions affected
Red Hat / Red Hat OpenStack Platform 17.1
All versions affected
Red Hat / Red Hat OpenStack Platform 17.1
All versions affected
Red Hat / Red Hat OpenStack Platform 17.1
All versions affected
Red Hat / Red Hat OpenStack Platform 17.1
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Service Interconnect 1
All versions affected
Red Hat / Red Hat Service Interconnect 1
All versions affected
Red Hat / Red Hat Service Interconnect 1
All versions affected
Red Hat / Red Hat Storage 3
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2024:10133 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7502 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:7550 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8327 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8678 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:8847 access.redhat.com: https://access.redhat.com/errata/RHSA-2024:9551 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:2416 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:7118 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:7256 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:7624 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-9355 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2315719 github.com: https://github.com/golang-fips/openssl/pull/198

Credits

This issue was discovered by David Benoit (Red Hat).