RHSA-2025:7620: Important: JBoss EAP XP 5.0 Update 2.0 release. See references for release notes.
Important: JBoss EAP XP 5.0 Update 2.0 release. See references for release notes.
Other sources
JBoss EAP XP 5.0 Update 2.0 GA release. See references for release notes.<br>Security Fix(es):<br><li> org.jboss.narayana-narayana-all: deadlock via multiple join requests sent to LRA Coordinator (CVE-2024-8447)</li> <li> com.google.protobuf/protobuf-java: StackOverflow vulnerability in Protocol Buffers (CVE-2024-7254)</li> <li> org.jboss.eap-jboss-eap-xp: StackOverflow vulnerability in Protocol Buffers (CVE-2024-7254)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:7620?
The severity of RHSA-2025:7620 is classified as important.
How do I fix RHSA-2025:7620?
To fix RHSA-2025:7620, update to JBoss EAP XP 5.0 Update 2.0 release.
What vulnerabilities are addressed in RHSA-2025:7620?
RHSA-2025:7620 addresses a deadlock vulnerability via multiple join requests sent to the LRA Coordinator.
Which product does RHSA-2025:7620 affect?
RHSA-2025:7620 affects JBoss Enterprise Application Platform.
What version of JBoss is affected by RHSA-2025:7620?
RHSA-2025:7620 affects JBoss EAP XP 5.0 before Update 2.0.