UBUNTU-CVE-2024-24786
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-24786
UBUNTU-CVE-2024-24786
Summary:
Details: The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
References: https://ubuntu.com/security/CVE-2024-24786, https://go-review.googlesource.com/c/protobuf/+/569356, https://go.dev/cl/569356, https://pkg.go.dev/vuln/GO-2024-2611, https://www.cve.org/CVERecord?id=CVE-2024-24786, https://ubuntu.com/security/notices/USN-6746-1, https://ubuntu.com/security/notices/USN-6746-2
Affected packages
Package
Name: google-osconfig-agent
Purl: pkg:deb/ubuntu/google-osconfig-agent?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
