RHSA-2024:2088: Important: Red Hat build of Cryostat security update
An update is now available for the Red Hat build of Cryostat 2 on RHEL 8.<br>Security Fix(es):<br><li> vert.x: io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx (CVE-2024-1023)</li> <li> vertx-core: io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support (CVE-2024-1300)</li> <li> golang: net/<a href="http:" target="blank">http:</a> memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)</li> <li> golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)</li> <li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> netty-codec-<a href="http:" target="blank">http:</a> Allocation of Resources Without Limits or Throttling (CVE-2024-29025)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Red Hat build of Cryostat security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2088?
The severity of RHSA-2024:2088 is classified as moderate due to the memory leak vulnerabilities identified.
How do I fix RHSA-2024:2088?
To fix RHSA-2024:2088, you should update to the latest version of the Red Hat Cryostat package that addresses the vulnerabilities.
What vulnerabilities are addressed in RHSA-2024:2088?
RHSA-2024:2088 addresses memory leak vulnerabilities in the vert.x and vertx-core components due to issues with Netty FastThreadLocal data structures.
Which systems are affected by RHSA-2024:2088?
RHSA-2024:2088 affects the Red Hat build of Cryostat 2 on RHEL 8.
What should I do if I cannot apply the update for RHSA-2024:2088?
If you cannot apply the update for RHSA-2024:2088, you should assess the risk of the vulnerabilities and consider implementing additional monitoring and mitigation strategies.