Описание
Narayana deadlock via multiple join requests sent to LRA Coordinator
A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-8447
- https://github.com/jbosstm/narayana/pull/2293
- https://github.com/jbosstm/narayana/commit/eb778412de230afc4687a2df43641280494156c5
- https://access.redhat.com/errata/RHSA-2025:3357
- https://access.redhat.com/errata/RHSA-2025:3358
- https://access.redhat.com/errata/RHSA-2025:7620
- https://access.redhat.com/security/cve/CVE-2024-8447
- https://bugzilla.redhat.com/show_bug.cgi?id=2335206
Пакеты
org.jboss.narayana.rts:lra-coordinator-jar
< 7.1.0.Final
7.1.0.Final
Связанные уязвимости
A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.