Описание
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
Отчет
Red Hat rates this issue as Moderate impact. Although cockpit-ws is reachable by an unauthenticated remote client and the resulting memory exhaustion can be sustained indefinitely, cockpit-ws is a stateless web console component: its crash or restart does not itself compromise the confidentiality or integrity of the host or of other running services, and the process is automatically restarted by systemd.
Меры по смягчению последствий
Restrict network access to the cockpit port to trusted clients until a fix is available. No configuration-level mitigation removes the flaw entirely, since the login page must remain reachable without authentication.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | cockpit | Affected | ||
| Red Hat Enterprise Linux 7 | cockpit | Affected | ||
| Red Hat Enterprise Linux 8 | cockpit | Affected | ||
| Red Hat Enterprise Linux 9 | cockpit | Affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/udi-base-rhel10 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/udi-base-rhel9 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
(A memory leak flaw was found in cockpit-ws. The login page handler lea ...)
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
A memory leak flaw was found in cockpit-ws. The login page handler lea ...
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
EPSS
7.5 High
CVSS3