REDHAT-BUG-1893070: Medium severity wildfly vulnerability
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Reference: https://issues.redhat.com/browse/WFCORE-5105 Upstream patch: https://github.com/wildfly/wildfly-core/pull/4308 Affected artifacts: wildfly-host-controller-VERSION.jar wildfly-protocol-VERSION.jar jboss-cli-client.jar
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1893070?
REDHAT-BUG-1893070 is considered a critical vulnerability due to its potential to cause Out of Memory (OOM) issues.
How do I fix REDHAT-BUG-1893070?
To fix REDHAT-BUG-1893070, upgrade to WildFly version 21.0.1.Final or later where the memory leak flaw has been addressed.
Which versions are affected by REDHAT-BUG-1893070?
REDHAT-BUG-1893070 affects all versions of WildFly up to and including version 21.0.0.Final.
What components are impacted by REDHAT-BUG-1893070?
REDHAT-BUG-1893070 impacts the WildFly server's host-controller that attempts to reconnect to the domain-controller.
What type of vulnerability is REDHAT-BUG-1893070?
REDHAT-BUG-1893070 is classified as a memory leak vulnerability affecting the connection handling in WildFly.