CVE-2024-24790: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
Published Jun 4, 2024
·Updated
Last updated 14 November 2024
Other sources
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
— Launchpad
Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
— Microsoft
Affected Software
16 affected componentsFixes available
Golang Go<1.21.11
Golang Go>=1.22.0<1.22.4
debian/golang-1.15<=1.15.15-1~deb11u4
debian/golang-1.19<=1.19.8-2
IBM Concert Software<=1.0.0-1.1.0
redhat/golang<1.22.4
1.22.4
redhat/golang<1.21.11
1.21.11
Microsoft cbl2 golang 1.22.7-3
Microsoft cbl2 msft-golang 1.21.6-1
Microsoft cbl2 golang 1.22.7-3
Microsoft cbl2 golang 1.17.13-2
Microsoft cbl2 golang 1.18.8-7
Microsoft cbl2 msft-golang 1.24.1-2
Microsoft cbl2 golang 1.18.8-4
Microsoft cbl2 golang 1.22.3-1
Microsoft cbl2 golang 1.21.11-1
Remediation
Patch Available
Event History
Jun 5, 2024
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionWeakness
Jun 17, 2024
Data Sourced
via Red Hat·10:04 PM
DescriptionSeverityAffected Software
Jul 9, 2024
Data Sourced
via Launchpad·03:35 PM
Description
Nov 15, 2024
Data Sourced
via Ubuntu·01:21 PM
RemedyDescriptionSeverityAffected Software
Sep 1, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·03:53 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·03:53 AM
Affected Software
Updated
via Microsoft·03:53 AM
SeverityAffected Software
Updated
via Microsoft·03:53 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-24790?
CVE-2024-24790 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-24790?
To remediate CVE-2024-24790, upgrade golang to versions 1.22.4 or later, or 1.21.11 for specific packages.
3
What systems are affected by CVE-2024-24790?
CVE-2024-24790 affects specific versions of golang in Red Hat and Debian packages.
4
What types of addresses are impacted by CVE-2024-24790?
CVE-2024-24790 affects the Is methods for IPv4-mapped IPv6 addresses.
5
Is CVE-2024-24790 a critical vulnerability?
No, CVE-2024-24790 is not classified as a critical vulnerability.