RHSA-2024:2833: Moderate: Service Registry (container images) release and security update [2.5.11 GA]
Moderate: Service Registry (container images) release and security update [2.5.11 GA]
Other sources
This release of Red Hat Integration - Service Registry 2.5.11 GA includes the following security fixes.<br>Security Fix(es):<br><li> commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file [rhint-serv-2] (CVE-2024-25710)</li> <li> vert.x: io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx [rhint-serv-2] (CVE-2024-1023)</li> <li> vertx-core: io.vertx:vertx-core: memory leak when a TCP server is configured with TLS and SNI support [rhint-serv-2] (CVE-2024-1300)</li> <li> commons-compress: OutOfMemoryError unpacking broken Pack200 file [rhint-serv-2] (CVE-2024-26308)</li> <li> netty-codec-<a href="http:" target="blank">http:</a> Allocation of Resources Without Limits or Throttling [rhint-serv-2] (CVE-2024-29025)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2833?
The severity of RHSA-2024:2833 is classified as moderate.
How do I fix RHSA-2024:2833?
To fix RHSA-2024:2833, update to the latest version of Red Hat Integration - Service Registry.
What kind of vulnerability does RHSA-2024:2833 address?
RHSA-2024:2833 addresses a denial of service vulnerability caused by an infinite loop in commons-compress.
Which product is affected by RHSA-2024:2833?
The affected product is Red Hat Integration - Service Registry.
Is there a workaround for RHSA-2024:2833?
There are no specific workarounds provided for RHSA-2024:2833; the recommended action is to apply the security update.