<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Opentelemetry-Collector (&lt; 124.0.6367.155) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/opentelemetry-collector--124.0.6367.155/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 14:01:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/opentelemetry-collector--124.0.6367.155/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector</title><link>https://feed.craftedsignal.io/briefs/2026-09-rhel-otel-dos/</link><pubDate>Fri, 25 Sep 2026 14:01:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rhel-otel-dos/</guid><description>A vulnerability in the opentelemetry-collector package within Red Hat Enterprise Linux allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting monitoring and telemetry data collection services.</description><content:encoded><![CDATA[<p>A vulnerability has been identified in the opentelemetry-collector package provided within Red Hat Enterprise Linux distributions. The issue, tracked as CVE-2024-4558, allows a remote, unauthenticated attacker to cause a denial of service condition. This impact is significant for environments relying on the collector for observability and infrastructure monitoring, as successful exploitation results in the cessation of data processing and reporting. Defenders should prioritize updating the opentelemetry-collector package to the patched version provided by Red Hat to restore the stability of telemetry pipelines.</p>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of this vulnerability results in a denial of service, rendering the opentelemetry-collector unresponsive. This causes a loss of observability data for systems monitored by the collector, potentially impacting the ability of security operations centers to ingest telemetry, logs, or metrics essential for incident detection and system performance monitoring.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching the affected infrastructure by applying the latest security updates released by Red Hat for the opentelemetry-collector package. Verify system stability post-patching to ensure that service interruptions related to CVE-2024-4558 are resolved.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>denial-of-service</category></item></channel></rss>