First published: Mon Apr 29 2024(Updated: )
An update is now available for the Red Hat build of Cryostat 2 on RHEL 8.<br>Security Fix(es):<br><li> vert.x: io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx (CVE-2024-1023)</li> <li> vertx-core: io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support (CVE-2024-1300)</li> <li> golang: net/<a href="http:" target="_blank">http:</a> memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)</li> <li> golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)</li> <li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> netty-codec-<a href="http:" target="_blank">http:</a> Allocation of Resources Without Limits or Throttling (CVE-2024-29025)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Cryostat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.