Описание
A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).
Отчет
Red Hat rates this vulnerability as an Important impact as the uncontrolled resource consumption may lead to Denial of Service (DoS). This might be intentioned by an attacker who is looking to jeopardize an environment.
Меры по смягчению последствий
There is currently no mitigation available for this vulnerability. Please keep the packages up-to-date as the updates become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 3 | xnio | Not affected | ||
| Red Hat build of Apache Camel - HawtIO 4 | xnio | Will not fix | ||
| Red Hat Build of Keycloak | xnio | Not affected | ||
| Red Hat Data Grid 8 | xnio | Not affected | ||
| Red Hat Integration Camel K 1 | xnio | Will not fix | ||
| Red Hat JBoss Data Grid 7 | xnio | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | xnio-nio | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | xnio-nio | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | xnio | Out of support scope | ||
| Red Hat Process Automation 7 | xnio | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).
A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).
A flaw was found in XNIO. The XNIO NotifierState that can cause a Stac ...
Уязвимость библиотеки для обеспечения неблокирующих операций ввода-вывода (I/O) XNIO, связанная с неконтролируемым потребление ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3