Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector
A vulnerability in the opentelemetry-collector package within Red Hat Enterprise Linux allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting monitoring and telemetry data collection services.
CVE search metadata
CVE search record: CVE-2024-4558. Severity: critical. CVSS: 9.6. EPSS: 1.53%. KEV: no. Product: opentelemetry-collector (< 124.0.6367.155). Brief: Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rhel-otel-dos/
A vulnerability has been identified in the opentelemetry-collector package provided within Red Hat Enterprise Linux distributions. The issue, tracked as CVE-2024-4558, allows a remote, unauthenticated attacker to cause a denial of service condition. This impact is significant for environments relying on the collector for observability and infrastructure monitoring, as successful exploitation results in the cessation of data processing and reporting. Defenders should prioritize updating the opentelemetry-collector package to the patched version provided by Red Hat to restore the stability of telemetry pipelines.
Impact
The successful exploitation of this vulnerability results in a denial of service, rendering the opentelemetry-collector unresponsive. This causes a loss of observability data for systems monitored by the collector, potentially impacting the ability of security operations centers to ingest telemetry, logs, or metrics essential for incident detection and system performance monitoring.
Recommendation
Prioritize patching the affected infrastructure by applying the latest security updates released by Red Hat for the opentelemetry-collector package. Verify system stability post-patching to ensure that service interruptions related to CVE-2024-4558 are resolved.
Mitigations
Upgrade opentelemetry-collector to 124.0.6367.155 or later
CVE-2024-4558