RHSA-2026:1823HighCVSS 7.5
Red Hat Security Advisory: JMC bug fix and enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-66566 — lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing
🎯 Affected products3
- Red Hat CodeReady Linux Builder EUS (v.9.4)
- jmc-0:8.2.0-17.el9_4.2.src as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- jmc-0:8.2.0-17.el9_4.2.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258