Описание
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cockpit | fixed | 366-1 | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2519497
https://github.com/cockpit-project/cockpit/pull/23633
Fixed by: https://github.com/cockpit-project/cockpit/commit/233b1c178dcb95ccef356832afd9d60023d601e9
EPSS
Связанные уязвимости
(A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
EPSS