Описание
A flaw was found in the Netty netty-codec-redis component. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted Redis protocol frames over long-lived connections. The Redis decoder fails to properly release allocated memory, leading to memory exhaustion and application instability.
Отчет
This vulnerability is rated as Important because a remote attacker can cause a denial of service in applications utilizing netty-codec-redis by sending specially crafted Redis protocol frames. The memory leak in long-lived Redis connections can lead to JVM heap exhaustion, making the service unavailable.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | netty-codec-redis | Fix deferred | ||
| Red Hat Data Grid 8 | netty-codec-redis | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | netty-codec-redis | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | netty-codec-redis | Fix deferred | ||
| Red Hat Single Sign-On 7 | netty-codec-redis | Out of support scope |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
7.5 High
CVSS3