Vulnerability CVE-2024-24783: Information

Description

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

Published: March 6, 2024
Modified: May 1, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
golangsisyphus1.22.1-alt11.22.3-alt1ALT-PU-2024-3506-1342122Fixed
golangsisyphus_riscv641.22.1-alt11.22.3-alt1ALT-PU-2024-4203-1-Fixed
golangsisyphus_loongarch641.22.1-alt11.22.3-alt1ALT-PU-2024-3594-1-Fixed
golangp101.21.8-alt11.21.10-alt1ALT-PU-2024-3504-2342123Fixed
golangc10f11.21.8-alt11.21.10-alt1ALT-PU-2024-4847-5343662Fixed

References to Advisories, Solutions, and Tools