RHSA-2024:4079: Low: [23.1] Security update for the 23.1 release (RPMs)
Low: [23.1] Security update for the 23.1 release (RPMs)
Other sources
The quarkus-mandrel-java and quarkus-mandrel-231 packages provide the<br>GraalVM installation for the quarkus/mandrel-for-jdk-21-rhel8:23.1 container image on top of the latest release of OpenJDK 21.0.3.<br>Security Fix(es):<br><li> org.graalvm.compiler/compiler: graalvm: Unauthorized Read Access</li> (CVE-2024-20954)<br><li> org.graalvm.compiler/compiler: graalvm: unauthorized ability to cause a partial denial of service</li> (CVE-2024-21098)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4079?
The severity of RHSA-2024:4079 is classified as low.
How do I fix RHSA-2024:4079?
To fix RHSA-2024:4079, update the quarkus-mandrel and quarkus-mandrel-java packages to the recommended versions.
Which software is affected by RHSA-2024:4079?
RHSA-2024:4079 affects the Red Hat build of Quarkus and several related Quarkus Mandrel packages.
What is the importance of updating for RHSA-2024:4079?
Updating for RHSA-2024:4079 is important to ensure security and stability of applications built using Quarkus.
When was RHSA-2024:4079 released?
RHSA-2024:4079 was released as part of the security update process for the 23.1 release.