RHSA-2024:6437: Moderate: Red Hat build of Quarkus 3.8.6 release and security update
Moderate: Red Hat build of Quarkus 3.8.6 release and security update
Other sources
This release of Red Hat build of Quarkus 3.8.6 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.<br>Security Fix(es):<br><li> EMBARGOED CVE-2024-3653 io.quarkus/quarkus-undertow: undertow: LearningPushHandler can lead to remote memory DoS attacks [quarkus-3.8]</li> <li> CVE-2024-8391 io.vertx.vertx-grpc-client: Vertx gRPC server does not limit the maximum message size [quarkus-3.8]</li> <li> CVE-2024-8391 io.vertx.vertx-grpc-server: Vertx gRPC server does not limit the maximum message size [quarkus-3.8]</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:6437?
RHSA-2024:6437 has a moderate severity rating.
How do I fix RHSA-2024:6437?
To fix RHSA-2024:6437, upgrade to the latest release of Red Hat build of Quarkus 3.8.6.
What software is affected by RHSA-2024:6437?
RHSA-2024:6437 affects the Red Hat build of Quarkus.
What type of updates are included in RHSA-2024:6437?
RHSA-2024:6437 includes security updates, bug fixes, and enhancements.
Is there additional information available for RHSA-2024:6437?
Yes, additional information regarding RHSA-2024:6437 can be found in the release notes.