RHSA-2024:1509MediumCVSS 5.5
Red Hat Security Advisory: Red Hat Data Grid 8.4.7 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-25710 — commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file CVE-2024-26308 — commons-compress: OutOfMemoryError unpacking broken Pack200 file
🎯 Affected products1
- Red Hat Data Grid
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available for this vulnerability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:1509
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/softwareDetail.html?softwareId=70381&product=data.grid&version=8.4&downloadType=patches
- externalhttps://access.redhat.com/documentation/en-us/red_hat_data_grid/8.4/html-single/red_hat_data_grid_8.4_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264988
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264989
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1509.json