Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.8 XP 6.0.6.GA release
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-24281 — Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing CVE-2026-24308 — Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
🎯 Affected products200
- Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.jboss-eap-xp-CR2-maven-repository.zip-6.0.7.GA as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.libartemis-native-32.so-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.libartemis-native-64.so-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.liblz4-java.so-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.libsnappyjava.so-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.libzstd-jni-1.5.6.10-rhel8-redhat-00001.so-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.pom.xml-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- None.wc-chatbot-0.1.2.jar-None as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- at.yawk.lz4.lz4-java-1.10.1.rhel8-redhat-00001-sources.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- at.yawk.lz4.lz4-java-1.10.1.rhel8-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- at.yawk.lz4.lz4-java-1.10.1.rhel8-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.fasterxml.jackson.jr.jackson-jr-objects-2.18.9.redhat-00003-sources.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.fasterxml.jackson.jr.jackson-jr-objects-2.18.9.redhat-00003.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.fasterxml.jackson.jr.jackson-jr-objects-2.18.9.redhat-00003.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.fasterxml.jackson.jr.jackson-jr-parent-2.18.9.redhat-00003.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.github.luben.zstd-jni-1.5.6.10-rhel8-redhat-00001-sources.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.github.luben.zstd-jni-1.5.6.10-rhel8-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.github.luben.zstd-jni-1.5.6.10-rhel8-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.github.stephenc.jcip.jcip-annotations-1.0.1.redhat-00001-sources.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.github.stephenc.jcip.jcip-annotations-1.0.1.redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.github.stephenc.jcip.jcip-annotations-1.0.1.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.api.grpc.proto-google-common-protos-2.0.1.redhat-00002-sources.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.api.grpc.proto-google-common-protos-2.0.1.redhat-00002.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.api.grpc.proto-google-common-protos-2.0.1.redhat-00002.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.code.gson.gson-2.9.1.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.protobuf.protobuf-java-3.25.5.redhat-00003.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.protobuf.protobuf-java-4.28.3.redhat-00001-sources.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.protobuf.protobuf-java-4.28.3.redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- com.google.protobuf.protobuf-java-4.28.3.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform 6.0.7.GA
- +170 more not shown
✅ Remediation
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, disable reverse DNS lookup in Apache ZooKeeper's client and quorum protocols. This can be achieved by configuring the `zookeeper.ssl.hostnameVerification.disableReverseDns` property to `true`. This configuration option is available in Apache ZooKeeper versions 3.8.6 and 3.9.5 and later. A restart of the ZooKeeper service will be required for the change to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:70421
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2445449
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2445451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452456
- externalhttps://issues.redhat.com/browse/JBEAP-33582
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70421.json