Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:9200 - Security Advisory
Issued:
2024-11-12
Updated:
2024-11-12

RHSA-2024:9200 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: runc security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for runc is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.

Security Fix(es):

  • golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x

Fixes

  • BZ - 2279814 - CVE-2024-24788 golang: net: malformed DNS message can cause infinite loop
  • RHEL-46380 - runc 1.1.13 in no FIPS OKD environments running on CentOS Stream CoreOS leads to opensslcrypto: can't initialize OpenSSL : openssl: can't retrieve OpenSSL version

CVEs

  • CVE-2024-24788

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.5_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
x86_64
runc-1.1.13-4.el9.x86_64.rpm SHA-256: 1d5a14734a25039ab25efcc4f744c9f6a18bb0cfc0066cf752807dffd7b77165
runc-debuginfo-1.1.13-4.el9.x86_64.rpm SHA-256: a0ba06b2676eaa7daac35bfa7bb2e498ba96b09b1b90f718ee29bb15887ab1af
runc-debugsource-1.1.13-4.el9.x86_64.rpm SHA-256: db1a3c549623a7dec423fa1b4ee72ad92b4b87375ec26fd047301ef2dd2472d8

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
x86_64
runc-1.1.13-4.el9.x86_64.rpm SHA-256: 1d5a14734a25039ab25efcc4f744c9f6a18bb0cfc0066cf752807dffd7b77165
runc-debuginfo-1.1.13-4.el9.x86_64.rpm SHA-256: a0ba06b2676eaa7daac35bfa7bb2e498ba96b09b1b90f718ee29bb15887ab1af
runc-debugsource-1.1.13-4.el9.x86_64.rpm SHA-256: db1a3c549623a7dec423fa1b4ee72ad92b4b87375ec26fd047301ef2dd2472d8

Red Hat Enterprise Linux Server - AUS 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
x86_64
runc-1.1.13-4.el9.x86_64.rpm SHA-256: 1d5a14734a25039ab25efcc4f744c9f6a18bb0cfc0066cf752807dffd7b77165
runc-debuginfo-1.1.13-4.el9.x86_64.rpm SHA-256: a0ba06b2676eaa7daac35bfa7bb2e498ba96b09b1b90f718ee29bb15887ab1af
runc-debugsource-1.1.13-4.el9.x86_64.rpm SHA-256: db1a3c549623a7dec423fa1b4ee72ad92b4b87375ec26fd047301ef2dd2472d8

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
s390x
runc-1.1.13-4.el9.s390x.rpm SHA-256: 07f5ca5ba61845c85afb9d3588ab6a281388cee0ce847b9a74d58aac285871fc
runc-debuginfo-1.1.13-4.el9.s390x.rpm SHA-256: 721ee2f6b36427eb6655332eb9e1c030a40f49ecf3afd0fb3a6752bc72eae952
runc-debugsource-1.1.13-4.el9.s390x.rpm SHA-256: 1464e1d9483a5637c12dddf2988f345ec4da8a74ab02927e98ecf885e6ba0118

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
s390x
runc-1.1.13-4.el9.s390x.rpm SHA-256: 07f5ca5ba61845c85afb9d3588ab6a281388cee0ce847b9a74d58aac285871fc
runc-debuginfo-1.1.13-4.el9.s390x.rpm SHA-256: 721ee2f6b36427eb6655332eb9e1c030a40f49ecf3afd0fb3a6752bc72eae952
runc-debugsource-1.1.13-4.el9.s390x.rpm SHA-256: 1464e1d9483a5637c12dddf2988f345ec4da8a74ab02927e98ecf885e6ba0118

Red Hat Enterprise Linux for Power, little endian 9

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
ppc64le
runc-1.1.13-4.el9.ppc64le.rpm SHA-256: 38aad2df68ba6fc8035df7ded446544763886b6372deabb64ffd8bfc082c7839
runc-debuginfo-1.1.13-4.el9.ppc64le.rpm SHA-256: 607a6381f8fa28b5fa539ce1a288effe4f7aec43876cceb79b6afe01bdd1f434
runc-debugsource-1.1.13-4.el9.ppc64le.rpm SHA-256: e856b98a5f4f37015da3a21493639c45e5cc41dd39d710b224c97ca13c64b642

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
ppc64le
runc-1.1.13-4.el9.ppc64le.rpm SHA-256: 38aad2df68ba6fc8035df7ded446544763886b6372deabb64ffd8bfc082c7839
runc-debuginfo-1.1.13-4.el9.ppc64le.rpm SHA-256: 607a6381f8fa28b5fa539ce1a288effe4f7aec43876cceb79b6afe01bdd1f434
runc-debugsource-1.1.13-4.el9.ppc64le.rpm SHA-256: e856b98a5f4f37015da3a21493639c45e5cc41dd39d710b224c97ca13c64b642

Red Hat Enterprise Linux for ARM 64 9

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
aarch64
runc-1.1.13-4.el9.aarch64.rpm SHA-256: aee95b521bfe9aaa28ce9e827d2fa0619d947493a4f9bc6d3b83ceaf44eb5a79
runc-debuginfo-1.1.13-4.el9.aarch64.rpm SHA-256: 4b252945435ae70ed68379a84d76e46a3b2d8f1179dbeaa87919f2399fa26dce
runc-debugsource-1.1.13-4.el9.aarch64.rpm SHA-256: 627922478a447679e2552c1706b4c1ab1af7f5dd7d0084bed4bf82f703cfb79d

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
aarch64
runc-1.1.13-4.el9.aarch64.rpm SHA-256: aee95b521bfe9aaa28ce9e827d2fa0619d947493a4f9bc6d3b83ceaf44eb5a79
runc-debuginfo-1.1.13-4.el9.aarch64.rpm SHA-256: 4b252945435ae70ed68379a84d76e46a3b2d8f1179dbeaa87919f2399fa26dce
runc-debugsource-1.1.13-4.el9.aarch64.rpm SHA-256: 627922478a447679e2552c1706b4c1ab1af7f5dd7d0084bed4bf82f703cfb79d

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
ppc64le
runc-1.1.13-4.el9.ppc64le.rpm SHA-256: 38aad2df68ba6fc8035df7ded446544763886b6372deabb64ffd8bfc082c7839
runc-debuginfo-1.1.13-4.el9.ppc64le.rpm SHA-256: 607a6381f8fa28b5fa539ce1a288effe4f7aec43876cceb79b6afe01bdd1f434
runc-debugsource-1.1.13-4.el9.ppc64le.rpm SHA-256: e856b98a5f4f37015da3a21493639c45e5cc41dd39d710b224c97ca13c64b642

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
x86_64
runc-1.1.13-4.el9.x86_64.rpm SHA-256: 1d5a14734a25039ab25efcc4f744c9f6a18bb0cfc0066cf752807dffd7b77165
runc-debuginfo-1.1.13-4.el9.x86_64.rpm SHA-256: a0ba06b2676eaa7daac35bfa7bb2e498ba96b09b1b90f718ee29bb15887ab1af
runc-debugsource-1.1.13-4.el9.x86_64.rpm SHA-256: db1a3c549623a7dec423fa1b4ee72ad92b4b87375ec26fd047301ef2dd2472d8

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
aarch64
runc-1.1.13-4.el9.aarch64.rpm SHA-256: aee95b521bfe9aaa28ce9e827d2fa0619d947493a4f9bc6d3b83ceaf44eb5a79
runc-debuginfo-1.1.13-4.el9.aarch64.rpm SHA-256: 4b252945435ae70ed68379a84d76e46a3b2d8f1179dbeaa87919f2399fa26dce
runc-debugsource-1.1.13-4.el9.aarch64.rpm SHA-256: 627922478a447679e2552c1706b4c1ab1af7f5dd7d0084bed4bf82f703cfb79d

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6

SRPM
runc-1.1.13-4.el9.src.rpm SHA-256: ac343fd8d8028cb28480faf915c8a6c9b8600cf2a865644befd940703d5c27a1
s390x
runc-1.1.13-4.el9.s390x.rpm SHA-256: 07f5ca5ba61845c85afb9d3588ab6a281388cee0ce847b9a74d58aac285871fc
runc-debuginfo-1.1.13-4.el9.s390x.rpm SHA-256: 721ee2f6b36427eb6655332eb9e1c030a40f49ecf3afd0fb3a6752bc72eae952
runc-debugsource-1.1.13-4.el9.s390x.rpm SHA-256: 1464e1d9483a5637c12dddf2988f345ec4da8a74ab02927e98ecf885e6ba0118

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility