Описание
A flaw was found in svxlink's FRN module. A server-supplied list item count is accepted without validation, allowing a malicious server to trigger unbounded memory allocation. This can lead to memory exhaustion and a denial of service.
Отчет
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Меры по смягчению последствий
Update svxlink to version 26.05.1 or later.
Дополнительная информация
Статус:
Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2513799svxlink: svxlink: Unbounded memory growth via unvalidated list count in FRN module