---
id: CVE-2024-9355
title: A vulnerability was found in Golang FIPS OpenSSL
summary: >-
  A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious
  user to randomly cause an uninitialized buffer length variable with a zeroed
  buffer to be returned in FIPS mode. It may also be possible to force a false
  posi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-457
vendor: golang-fips
product: github.com/golang-fips/openssl
affected:
  - github.com/golang-fips/openssl <= 2.0.3
patched:
  - satellite_client_6_for_rhel 10
  - enterprise_linux_server_v_7_els
  - satellite_client_6_for_rhel 8
  - satellite_client_6_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_v_9
  - enterprise_linux_appstream_eus_v_9_6
  - trusted_artifact_signer 1.3
  - streams_for_apache_kafka 2.9.0
published: '2024-10-01'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:17:05.100'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-9355'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:10133'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:7502'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:7550'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8327'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8678'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8847'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:9551'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2416'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:7118'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:7256'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:7624'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:55520'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:55525'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:59439'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:66016'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68504'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69235'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-9355'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2315719'
    label: secalert@redhat.com
  - url: 'https://github.com/golang-fips/openssl/pull/198'
    label: secalert@redhat.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-9355'
  - url: 'https://pkg.go.dev/vuln/GO-2024-3167'
  - url: 'https://github.com/github/advisory-database/pull/4950'
  - url: 'https://github.com/advisories/GHSA-3h3x-2hwv-hr52'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-9355.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-9355'
  - url: 'https://github.com/golang-fips/openssl'
tags:
  - nvd
  - ghsa
  - go
  - cve.org
  - csaf
  - vex
  - red-hat
  - osv
aliases:
  - GHSA-3h3x-2hwv-hr52
  - GO-2024-3167
ecosystem: go
epss: 0.00298
epssPercentile: 0.22676
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-10-01T18:35:51.670441Z'
ingestedAt: '2026-08-05T11:47:23.390Z'
---

## Overview

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2024-9355)

Affected packages:

- `github.com/golang-fips/openssl <= 2.0.3`

Source: https://github.com/advisories/GHSA-3h3x-2hwv-hr52

## Vendor advisories

- **RHSA-2025:7624** · Red Hat · fixed in: Satellite Client 6 for RHEL 10, Satellite Client 6 for RHEL 8, Satellite Client 6 for RHEL 9 · released 2025-05-14 · [advisory](https://access.redhat.com/errata/RHSA-2025:7624)
- **RHSA-2024:10133** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2024-11-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:10133)
- **RHSA-2024:7502** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2024-10-02 · [advisory](https://access.redhat.com/errata/RHSA-2024:7502)
- **RHSA-2024:8327** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2024-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2024:8327)
- **RHSA-2024:8847** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2024-11-05 · [advisory](https://access.redhat.com/errata/RHSA-2024:8847)
- **RHSA-2026:55525** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55525)
- **RHSA-2024:9551** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.4) · released 2024-11-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:9551)
- **RHSA-2024:7550** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2024-10-02 · [advisory](https://access.redhat.com/errata/RHSA-2024:7550)
- **RHSA-2024:8678** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2024-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2024:8678)
- **RHSA-2025:7256** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2025-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:7256)
- **RHSA-2025:7118** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2025-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:7118)
- **Red Hat VEX** · Moderate · affected: NBDE Tang Server, OpenShift Developer Tools and Services, OpenShift Pipelines, OpenShift Serverless, Red Hat Ansible Automation Platform 1.2, Red Hat Ansible Automation Platform 2, … · no fix planned: OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-9355.json)
- **RHSA-2026:66016** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66016)
- **RHSA-2026:68504** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68504)
- **RHSA-2026:69235** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69235)
