Описание
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | wildfly-iiop-openjdk | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | wildfly-iiop-openjdk | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | wildfly-iiop-openjdk | Not affected | ||
| Red Hat Single Sign-On 7 | wildfly-iiop-openjdk | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7.4.25 | wildfly-iiop-openjdk | Fixed | RHSA-2026:53806 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
A flaw was found in Wildfly. A remote unauthenticated attacker can tri ...
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
EPSS
7.5 High
CVSS3