RHSA-2025:7620HighCVSS 7.5
Red Hat Security Advisory: JBoss EAP XP 5.0 Update 2.0 release. See references for release notes.
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-8447 — narayana: deadlock via multiple join requests sent to LRA Coordinator
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2025:7620
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2335206
- externalhttps://issues.redhat.com/browse/JBEAP-26539
- externalhttps://issues.redhat.com/browse/JBEAP-27340
- externalhttps://issues.redhat.com/browse/JBEAP-27477
- externalhttps://issues.redhat.com/browse/JBEAP-28933
- externalhttps://issues.redhat.com/browse/JBEAP-29471
- externalhttps://issues.redhat.com/browse/JBEAP-29737
- externalhttps://issues.redhat.com/browse/JBEAP-29738
- externalhttps://issues.redhat.com/browse/JBEAP-30007
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_7620.json