First published: Mon Aug 09 2021(Updated: )
A vulnerability was found in Undertow where buffer leak on incoming websocket PONG message may lead to memory exhaustion. <a href="https://issues.redhat.com/browse/UNDERTOW-1935">https://issues.redhat.com/browse/UNDERTOW-1935</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Undertow |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability REDHAT-BUG-1991299 is rated as a high severity issue due to potential memory exhaustion.
To address REDHAT-BUG-1991299, you should update to the latest version of Red Hat Undertow that contains the patch for this vulnerability.
REDHAT-BUG-1991299 is caused by a buffer leak occurring on incoming websocket PONG messages, which can lead to memory exhaustion.
Unfortunately, specific versions vulnerable to REDHAT-BUG-1991299 are not explicitly stated but typically recent releases are affected.
There are no recommended workarounds for REDHAT-BUG-1991299; updating to the patched version is the best approach.