CVE-2024-34156
HighAdvisory
Published 6 Sept 2024In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.011
- 65th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,403
- of 17,821 indexed, latest versions
- Container images
- 2,845
- deployed by those charts
- Fix available
- 9 of 10
- affected packages
Red Hat Security Advisory: skopeo security update
Carried by container images the latest versions of 2,403 of 17,821 indexed charts deploy, on 2,845 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| skopeorpm | 2:1.11.2-0.1.el9, 2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c | 2:1.11.2-0.3.module+el8.8.0+22332+2132e5c3, 2:1.16.1-2.el9_5 | 2 |
| containers-commonrpm | 2:1-64.module+el8.8.0+18571+eed59fc4 | 2:1-66.module+el8.8.0+22332+2132e5c3 | 1 |
| criurpm | 3.15-4.module+el8.8.0+19044+f9982fd8 | 0:3.15-4.module+el8.8.0+22332+2132e5c3 | 1 |
| fuse-overlayfsrpm | 1.11-1.module+el8.8.0+18634+9a268292 | 0:1.11-1.module+el8.8.0+22332+2132e5c3 | 1 |
| git-lfsrpm | 2.13.3-3.el8_6 | 0:3.4.1-3.el8_10 | 1 |
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| libslirprpm | 4.4.0-1.module+el8.8.0+18060+3f21f2cc | 0:4.4.0-1.module+el8.8.0+22332+2132e5c3 | 1 |
| runcrpm | 1:1.1.4-1.module+el8.8.0+18060+3f21f2cc | 1:1.1.12-1.module+el8.8.0+22332+2132e5c3 | 1 |
| slirp4netnsrpm | 1.2.0-2.module+el8.8.0+18060+3f21f2cc | 0:1.2.0-3.module+el8.8.0+22332+2132e5c3 | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+137 more | 1.22.7 | 2,845 |
- OSV records
- DEBIAN-CVE-2024-34156RHSA-2024:11217RHSA-2024:7135RHSA-2024:7769GO-2024-3106
- Also known as
- BIT-golang-2024-34156, RHSA-2024:7455, RHSA-2024:7821, RHSA-2024:8111
Charts affected
2,403 by stars
Container images carrying it
2,845 by charts deploying them
A fixed version is listed for 9 of the 10 affected packages.