RHSA-2025:1154: Important: Red Hat Integration Camel K 1.10.9 release and security update.
Camel K 1.10.9 is now available.The purpose of this text-only errata is to inform you about the security issues fixed.Security Fix(es): libsoup: buffer overflow via UTF-8 conversion in soupheaderparseparamliststrict (CVE-2024-52531) JDK: Enhance array handling (Oracle CPU 2025-01) (CVE-2025-21502) bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail). (CVE-2019-12900) graalvm: Unauthorized Read Access (CVE-2024-20954) graalvm: unauthorized ability to cause a partial denial of service (CVE-2024-21098) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE important page(s) listed in the References section.
Other sources
Important: Red Hat Integration Camel K 1.10.9 release and security update.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security issues are addressed in RHSA-2025:1154?
RHSA-2025:1154 addresses a buffer overflow vulnerability in libsoup that can occur during UTF-8 conversion in soup_header_parse_param_list_strict (CVE-2024-52531).
What is the severity of RHSA-2025:1154?
The severity of RHSA-2025:1154 is critical due to the potential for exploiting the buffer overflow vulnerability.
How do I fix RHSA-2025:1154?
To fix RHSA-2025:1154, update your Red Hat Integration - Camel K to version 1.10.9 or later.
What product is affected by the RHSA-2025:1154 vulnerability?
The affected product for RHSA-2025:1154 is Red Hat Integration - Camel K.
Is there a workaround for RHSA-2025:1154?
There are no documented workarounds for RHSA-2025:1154; the recommended action is to apply the security update.