{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"important"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2024-37298","title":"Title"},{"category":"description","text":"gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2024-37298","url":"https://www.suse.com/security/cve/CVE-2024-37298"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1227309 for CVE-2024-37298","url":"https://bugzilla.suse.com/1227309"},{"category":"external","summary":"Advisory link for RHSA-2024:6194","url":"https://lists.suse.com/pipermail/suse-liberty-linux-updates/2024-September/000019.html"},{"category":"external","summary":"Advisory link for openSUSE-SU-2025:14663-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IL7QOYRPFRGRS6UKU6ZYHI76FWFFUJNK/"}],"title":"SUSE CVE CVE-2024-37298","tracking":{"current_release_date":"2025-11-03T01:46:15Z","generator":{"date":"2024-07-03T03:17:35Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2024-37298","initial_release_date":"2024-07-03T03:17:35Z","revision_history":[{"date":"2024-07-03T03:17:35Z","number":"2","summary":"Current version"},{"date":"2024-08-16T02:06:54Z","number":"3","summary":"Current version"},{"date":"2024-09-11T03:03:56Z","number":"4","summary":"Current version"},{"date":"2024-09-27T03:27:29Z","number":"5","summary":"Current version"},{"date":"2025-01-01T01:02:11Z","number":"6","summary":"Current version"},{"date":"2025-01-18T03:58:24Z","number":"7","summary":"Current version"},{"date":"2025-01-19T03:57:37Z","number":"8","summary":"Current version"},{"date":"2025-01-25T04:13:32Z","number":"9","summary":"Current version"},{"date":"2025-02-14T04:54:42Z","number":"10","summary":"Current version"},{"date":"2025-02-16T04:46:54Z","number":"11","summary":"Current version"},{"date":"2025-03-15T05:02:24Z","number":"12","summary":"Current version"},{"date":"2025-04-24T13:44:51Z","number":"13","summary":"Current version"},{"date":"2025-11-01T04:10:51Z","number":"14","summary":"Current version"},{"date":"2025-11-03T01:46:15Z","number":"15","summary":"Current version"}],"status":"interim","version":"15"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Liberty Linux 8","product":{"name":"SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8","product_identification_helper":{"cpe":"cpe:/o:suse:sll:8"}}},{"category":"product_name","name":"SUSE Liberty Linux 9","product":{"name":"SUSE Liberty Linux 9","product_id":"SUSE Liberty Linux 9","product_identification_helper":{"cpe":"cpe:/o:suse:sll:9"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 16.0","product":{"name":"SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0","product_identification_helper":{"cpe":"cpe:/o:suse:sles:16.0"}}},{"category":"product_name","name":"SUSE Package Hub 15 SP6","product":{"name":"SUSE Package Hub 15 SP6","product_id":"SUSE Package Hub 15 SP6"}},{"category":"product_name","name":"openSUSE Leap 15.6","product":{"name":"openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.6"}}},{"category":"product_name","name":"openSUSE Tumbleweed","product":{"name":"openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed","product_identification_helper":{"cpe":"cpe:/o:opensuse:tumbleweed"}}},{"category":"product_version","name":"aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65","product":{"name":"aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65","product_id":"aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:containers:aardvark-dns:1.10.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"buildah-1.33.8-4.module+el8.10.0+22202+761b9a65","product":{"name":"buildah-1.33.8-4.module+el8.10.0+22202+761b9a65","product_id":"buildah-1.33.8-4.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:buildah_project:buildah:1.33.8:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/buildah-1.33.8-4.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65","product":{"name":"buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65","product_id":"buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65","product":{"name":"cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65","product_id":"cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"conmon-2.1.10-1.module+el8.10.0+22202+761b9a65","product":{"name":"conmon-2.1.10-1.module+el8.10.0+22202+761b9a65","product_id":"conmon-2.1.10-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/conmon-2.1.10-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65","product":{"name":"container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65","product_id":"container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65","product":{"name":"containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65","product_id":"containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"containers-common-1-82.module+el8.10.0+22202+761b9a65","product":{"name":"containers-common-1-82.module+el8.10.0+22202+761b9a65","product_id":"containers-common-1-82.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/containers-common-1-82.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"crit-3.18-5.module+el8.10.0+22202+761b9a65","product":{"name":"crit-3.18-5.module+el8.10.0+22202+761b9a65","product_id":"crit-3.18-5.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/crit-3.18-5.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"criu-3.18-5.module+el8.10.0+22202+761b9a65","product":{"name":"criu-3.18-5.module+el8.10.0+22202+761b9a65","product_id":"criu-3.18-5.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:criu:checkpoint\\/restore_in_userspace:3.18:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/criu-3.18-5.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"criu-devel-3.18-5.module+el8.10.0+22202+761b9a65","product":{"name":"criu-devel-3.18-5.module+el8.10.0+22202+761b9a65","product_id":"criu-devel-3.18-5.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/criu-devel-3.18-5.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"criu-libs-3.18-5.module+el8.10.0+22202+761b9a65","product":{"name":"criu-libs-3.18-5.module+el8.10.0+22202+761b9a65","product_id":"criu-libs-3.18-5.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/criu-libs-3.18-5.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"crun-1.14.3-2.module+el8.10.0+22202+761b9a65","product":{"name":"crun-1.14.3-2.module+el8.10.0+22202+761b9a65","product_id":"crun-1.14.3-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:crun_project:crun:1.14.3:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/crun-1.14.3-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65","product":{"name":"fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65","product_id":"fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65","product":{"name":"libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65","product_id":"libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:libslirp_project:libslirp:4.4.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65","product":{"name":"libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65","product_id":"libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"netavark-1.10.3-1.module+el8.10.0+22202+761b9a65","product":{"name":"netavark-1.10.3-1.module+el8.10.0+22202+761b9a65","product_id":"netavark-1.10.3-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/netavark-1.10.3-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65","product":{"name":"oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65","product_id":"oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-4.9.4-10.el9_4","product":{"name":"podman-4.9.4-10.el9_4","product_id":"podman-4.9.4-10.el9_4","product_identification_helper":{"cpe":"cpe:2.3:a:podman_project:podman:4.9.4:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/podman@4.9.4-10.el9_4?upstream=podman-4.9.4-10.el9_4.src.rpm"}}},{"category":"product_version","name":"podman-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:podman_project:podman:4.9.4:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/podman-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-docker-4.9.4-10.el9_4","product":{"name":"podman-docker-4.9.4-10.el9_4","product_id":"podman-docker-4.9.4-10.el9_4","product_identification_helper":{"cpe":"cpe:2.3:a:podman_project:podman:4.9.4:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/podman-docker@4.9.4-10.el9_4?upstream=podman-4.9.4-10.el9_4.src.rpm"}}},{"category":"product_version","name":"podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-plugins-4.9.4-10.el9_4","product":{"name":"podman-plugins-4.9.4-10.el9_4","product_id":"podman-plugins-4.9.4-10.el9_4","product_identification_helper":{"purl":"pkg:rpm/suse/podman-plugins@4.9.4-10.el9_4"}}},{"category":"product_version","name":"podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-remote-4.9.4-10.el9_4","product":{"name":"podman-remote-4.9.4-10.el9_4","product_id":"podman-remote-4.9.4-10.el9_4","product_identification_helper":{"cpe":"cpe:2.3:a:podman_project:podman:4.9.4:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/podman-remote@4.9.4-10.el9_4?upstream=podman-4.9.4-10.el9_4.src.rpm"}}},{"category":"product_version","name":"podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"podman-tests-4.9.4-10.el9_4","product":{"name":"podman-tests-4.9.4-10.el9_4","product_id":"podman-tests-4.9.4-10.el9_4","product_identification_helper":{"purl":"pkg:rpm/suse/podman-tests@4.9.4-10.el9_4"}}},{"category":"product_version","name":"podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65","product":{"name":"podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65","product_id":"podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"python3-criu-3.18-5.module+el8.10.0+22202+761b9a65","product":{"name":"python3-criu-3.18-5.module+el8.10.0+22202+761b9a65","product_id":"python3-criu-3.18-5.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/python3-criu-3.18-5.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65","product":{"name":"python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65","product_id":"python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"runc-1.1.12-4.module+el8.10.0+22202+761b9a65","product":{"name":"runc-1.1.12-4.module+el8.10.0+22202+761b9a65","product_id":"runc-1.1.12-4.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:linuxfoundation:runc:1.1.12:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/runc-1.1.12-4.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65","product":{"name":"skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65","product_id":"skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65","product":{"name":"skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65","product_id":"skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65","product":{"name":"slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65","product_id":"slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65","product_identification_helper":{"cpe":"cpe:2.3:a:libslirp_project:libslirp:1.2.3:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"system-user-velociraptor-1.0.0-160000.2.2","product":{"name":"system-user-velociraptor-1.0.0-160000.2.2","product_id":"system-user-velociraptor-1.0.0-160000.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:1.0.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/system-user-velociraptor@1.0.0-160000.2.2?upstream=velociraptor-1.0.0-160000.2.2.src.rpm"}}},{"category":"product_version","name":"system-user-velociraptor-1.0.0-bp156.3.3.1","product":{"name":"system-user-velociraptor-1.0.0-bp156.3.3.1","product_id":"system-user-velociraptor-1.0.0-bp156.3.3.1","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:1.0.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/system-user-velociraptor@1.0.0-bp156.3.3.1?upstream=velociraptor-1.0.0-bp156.3.3.1.src.rpm"}}},{"category":"product_version","name":"toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65","product":{"name":"toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65","product_id":"toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65","product":{"name":"toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65","product_id":"toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"udica-0.2.6-21.module+el8.10.0+22202+761b9a65","product":{"name":"udica-0.2.6-21.module+el8.10.0+22202+761b9a65","product_id":"udica-0.2.6-21.module+el8.10.0+22202+761b9a65","product_identification_helper":{"purl":"pkg:rpm/suse/udica-0.2.6-21.module+el8.10.0+22202+761b9a65@"}}},{"category":"product_version","name":"velociraptor-0.7.0.4.git142.862ef23-1.1","product":{"name":"velociraptor-0.7.0.4.git142.862ef23-1.1","product_id":"velociraptor-0.7.0.4.git142.862ef23-1.1","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:0.7.0.4.git142.862ef23:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/velociraptor@0.7.0.4.git142.862ef23-1.1?upstream=velociraptor-0.7.0.4.git142.862ef23-1.1.src.rpm"}}},{"category":"product_version","name":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","product":{"name":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","product_id":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:0.7.0.4.git142.862ef23:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/velociraptor@0.7.0.4.git142.862ef23-bp156.3.3.1?upstream=velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1.src.rpm"}}},{"category":"product_version","name":"velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2","product":{"name":"velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2","product_id":"velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:0.7.0.4.git152.fb24dfd:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/velociraptor@0.7.0.4.git152.fb24dfd-160000.2.2?upstream=velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2.src.rpm"}}},{"category":"product_version","name":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","product":{"name":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","product_id":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:0.7.0.4.git142.862ef23:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/velociraptor-client@0.7.0.4.git142.862ef23-bp156.3.3.1?upstream=velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1.src.rpm"}}},{"category":"product_version","name":"velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2","product":{"name":"velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2","product_id":"velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:rapid7:velociraptor:0.7.0.4.git152.fb24dfd:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/velociraptor-client@0.7.0.4.git152.fb24dfd-160000.2.2?upstream=velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2.src.rpm"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65"},"product_reference":"aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"buildah-1.33.8-4.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:buildah-1.33.8-4.module+el8.10.0+22202+761b9a65"},"product_reference":"buildah-1.33.8-4.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65"},"product_reference":"buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65"},"product_reference":"cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"conmon-2.1.10-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:conmon-2.1.10-1.module+el8.10.0+22202+761b9a65"},"product_reference":"conmon-2.1.10-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65"},"product_reference":"container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65"},"product_reference":"containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"containers-common-1-82.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:containers-common-1-82.module+el8.10.0+22202+761b9a65"},"product_reference":"containers-common-1-82.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"crit-3.18-5.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:crit-3.18-5.module+el8.10.0+22202+761b9a65"},"product_reference":"crit-3.18-5.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"criu-3.18-5.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:criu-3.18-5.module+el8.10.0+22202+761b9a65"},"product_reference":"criu-3.18-5.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"criu-devel-3.18-5.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:criu-devel-3.18-5.module+el8.10.0+22202+761b9a65"},"product_reference":"criu-devel-3.18-5.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"criu-libs-3.18-5.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:criu-libs-3.18-5.module+el8.10.0+22202+761b9a65"},"product_reference":"criu-libs-3.18-5.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"crun-1.14.3-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:crun-1.14.3-2.module+el8.10.0+22202+761b9a65"},"product_reference":"crun-1.14.3-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65"},"product_reference":"fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65"},"product_reference":"libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65"},"product_reference":"libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"netavark-1.10.3-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:netavark-1.10.3-1.module+el8.10.0+22202+761b9a65"},"product_reference":"netavark-1.10.3-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65"},"product_reference":"oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65"},"product_reference":"podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"python3-criu-3.18-5.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:python3-criu-3.18-5.module+el8.10.0+22202+761b9a65"},"product_reference":"python3-criu-3.18-5.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65"},"product_reference":"python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"runc-1.1.12-4.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:runc-1.1.12-4.module+el8.10.0+22202+761b9a65"},"product_reference":"runc-1.1.12-4.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65"},"product_reference":"skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65"},"product_reference":"skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65"},"product_reference":"slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65"},"product_reference":"toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65"},"product_reference":"toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"udica-0.2.6-21.module+el8.10.0+22202+761b9a65 as component of SUSE Liberty Linux 8","product_id":"SUSE Liberty Linux 8:udica-0.2.6-21.module+el8.10.0+22202+761b9a65"},"product_reference":"udica-0.2.6-21.module+el8.10.0+22202+761b9a65","relates_to_product_reference":"SUSE Liberty Linux 8"},{"category":"default_component_of","full_product_name":{"name":"podman-4.9.4-10.el9_4 as component of SUSE Liberty Linux 9","product_id":"SUSE Liberty Linux 9:podman-4.9.4-10.el9_4"},"product_reference":"podman-4.9.4-10.el9_4","relates_to_product_reference":"SUSE Liberty Linux 9"},{"category":"default_component_of","full_product_name":{"name":"podman-docker-4.9.4-10.el9_4 as component of SUSE Liberty Linux 9","product_id":"SUSE Liberty Linux 9:podman-docker-4.9.4-10.el9_4"},"product_reference":"podman-docker-4.9.4-10.el9_4","relates_to_product_reference":"SUSE Liberty Linux 9"},{"category":"default_component_of","full_product_name":{"name":"podman-plugins-4.9.4-10.el9_4 as component of SUSE Liberty Linux 9","product_id":"SUSE Liberty Linux 9:podman-plugins-4.9.4-10.el9_4"},"product_reference":"podman-plugins-4.9.4-10.el9_4","relates_to_product_reference":"SUSE Liberty Linux 9"},{"category":"default_component_of","full_product_name":{"name":"podman-remote-4.9.4-10.el9_4 as component of SUSE Liberty Linux 9","product_id":"SUSE Liberty Linux 9:podman-remote-4.9.4-10.el9_4"},"product_reference":"podman-remote-4.9.4-10.el9_4","relates_to_product_reference":"SUSE Liberty Linux 9"},{"category":"default_component_of","full_product_name":{"name":"podman-tests-4.9.4-10.el9_4 as component of SUSE Liberty Linux 9","product_id":"SUSE Liberty Linux 9:podman-tests-4.9.4-10.el9_4"},"product_reference":"podman-tests-4.9.4-10.el9_4","relates_to_product_reference":"SUSE Liberty Linux 9"},{"category":"default_component_of","full_product_name":{"name":"system-user-velociraptor-1.0.0-160000.2.2 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:system-user-velociraptor-1.0.0-160000.2.2"},"product_reference":"system-user-velociraptor-1.0.0-160000.2.2","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2"},"product_reference":"velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2"},"product_reference":"velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"system-user-velociraptor-1.0.0-bp156.3.3.1 as component of SUSE Package Hub 15 SP6","product_id":"SUSE Package Hub 15 SP6:system-user-velociraptor-1.0.0-bp156.3.3.1"},"product_reference":"system-user-velociraptor-1.0.0-bp156.3.3.1","relates_to_product_reference":"SUSE Package Hub 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1 as component of SUSE Package Hub 15 SP6","product_id":"SUSE Package Hub 15 SP6:velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1"},"product_reference":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","relates_to_product_reference":"SUSE Package Hub 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1 as component of SUSE Package Hub 15 SP6","product_id":"SUSE Package Hub 15 SP6:velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1"},"product_reference":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","relates_to_product_reference":"SUSE Package Hub 15 SP6"},{"category":"default_component_of","full_product_name":{"name":"system-user-velociraptor-1.0.0-bp156.3.3.1 as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:system-user-velociraptor-1.0.0-bp156.3.3.1"},"product_reference":"system-user-velociraptor-1.0.0-bp156.3.3.1","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1 as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1"},"product_reference":"velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1 as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1"},"product_reference":"velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"velociraptor-0.7.0.4.git142.862ef23-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:velociraptor-0.7.0.4.git142.862ef23-1.1"},"product_reference":"velociraptor-0.7.0.4.git142.862ef23-1.1","relates_to_product_reference":"openSUSE Tumbleweed"}]},"vulnerabilities":[{"cve":"CVE-2024-37298","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2024-37298"}],"notes":[{"category":"general","text":"gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.","title":"CVE description"}],"product_status":{"recommended":["SUSE Liberty Linux 8:aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:buildah-1.33.8-4.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:conmon-2.1.10-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:containers-common-1-82.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:crit-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:criu-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:criu-devel-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:criu-libs-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:crun-1.14.3-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:netavark-1.10.3-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:python3-criu-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:runc-1.1.12-4.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:udica-0.2.6-21.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 9:podman-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-docker-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-plugins-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-remote-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-tests-4.9.4-10.el9_4","SUSE Linux Enterprise Server 16.0:system-user-velociraptor-1.0.0-160000.2.2","SUSE Linux Enterprise Server 16.0:velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2","SUSE Linux Enterprise Server 16.0:velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2","SUSE Package Hub 15 SP6:system-user-velociraptor-1.0.0-bp156.3.3.1","SUSE Package Hub 15 SP6:velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","SUSE Package Hub 15 SP6:velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","openSUSE Leap 15.6:system-user-velociraptor-1.0.0-bp156.3.3.1","openSUSE Leap 15.6:velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","openSUSE Leap 15.6:velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","openSUSE Tumbleweed:velociraptor-0.7.0.4.git142.862ef23-1.1"]},"references":[{"category":"external","summary":"CVE-2024-37298","url":"https://www.suse.com/security/cve/CVE-2024-37298"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1227309 for CVE-2024-37298","url":"https://bugzilla.suse.com/1227309"},{"category":"external","summary":"Advisory link for RHSA-2024:6194","url":"https://lists.suse.com/pipermail/suse-liberty-linux-updates/2024-September/000019.html"},{"category":"external","summary":"Advisory link for openSUSE-SU-2025:14663-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IL7QOYRPFRGRS6UKU6ZYHI76FWFFUJNK/"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["SUSE Liberty Linux 8:aardvark-dns-1.10.0-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:buildah-1.33.8-4.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:buildah-tests-1.33.8-4.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:cockpit-podman-84.1-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:conmon-2.1.10-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:container-selinux-2.229.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:containernetworking-plugins-1.4.0-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:containers-common-1-82.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:crit-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:criu-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:criu-devel-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:criu-libs-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:crun-1.14.3-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:fuse-overlayfs-1.13-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:libslirp-4.4.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:libslirp-devel-4.4.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:netavark-1.10.3-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-catatonit-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-docker-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-gvproxy-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-plugins-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-remote-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:podman-tests-4.9.4-12.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:python3-criu-3.18-5.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:python3-podman-4.9.0-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:runc-1.1.12-4.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:skopeo-1.14.5-3.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:skopeo-tests-1.14.5-3.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:slirp4netns-1.2.3-1.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:toolbox-0.0.99.5-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:toolbox-tests-0.0.99.5-2.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 8:udica-0.2.6-21.module+el8.10.0+22202+761b9a65","SUSE Liberty Linux 9:podman-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-docker-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-plugins-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-remote-4.9.4-10.el9_4","SUSE Liberty Linux 9:podman-tests-4.9.4-10.el9_4","SUSE Linux Enterprise Server 16.0:system-user-velociraptor-1.0.0-160000.2.2","SUSE Linux Enterprise Server 16.0:velociraptor-0.7.0.4.git152.fb24dfd-160000.2.2","SUSE Linux Enterprise Server 16.0:velociraptor-client-0.7.0.4.git152.fb24dfd-160000.2.2","SUSE Package Hub 15 SP6:system-user-velociraptor-1.0.0-bp156.3.3.1","SUSE Package Hub 15 SP6:velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","SUSE Package Hub 15 SP6:velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","openSUSE Leap 15.6:system-user-velociraptor-1.0.0-bp156.3.3.1","openSUSE Leap 15.6:velociraptor-0.7.0.4.git142.862ef23-bp156.3.3.1","openSUSE Leap 15.6:velociraptor-client-0.7.0.4.git142.862ef23-bp156.3.3.1","openSUSE Tumbleweed:velociraptor-0.7.0.4.git142.862ef23-1.1"]}],"threats":[{"category":"impact","date":"2024-07-01T20:00:57Z","details":"important"}],"title":"CVE-2024-37298"}]}