Bug 2264988 (CVE-2024-25710)

Summary: CVE-2024-25710 commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, adudiak, adupliak, aileenc, anstephe, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, ccranfor, cdewolf, chazlett, chfoley, clement.escoffier, cmiranda, cmoulliard, csutherl, dandread, darran.lofthouse, dfreiber, dhanak, dkreling, dosoudil, dpalmer, drichtar, drow, dsimansk, eaguilar, ebaron, ecerquei, epacific, eric.wittmann, fjansen, fjuma, fmariani, fmongiar, gmalinko, gsmet, ibek, ikanello, ivassile, iweiss, janstey, jburrell, jcammara, jcantril, jclere, jhardy, jkang, jmartisk, jneedle, jnethert, jobarker, jpallich, jpechane, jpoth, jrokos, jross, jsamir, jscholz, jwon, kaycoth, kingland, kshier, kverlaen, lgao, lthon, mabashia, matzew, max.andersen, mmadzin, mnovotny, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, olubyans, pantinor, pcongius, pdelbell, pdrozd, peholase, pgallagh, pierdipi, pjindal, pmackay, probinso, pskopek, rguimara, rhuss, rjohnson, rkieley, rowaters, rruss, rstancel, rsvoboda, saroy, sausingh, sbiarozk, sfroberg, simaishi, smaestri, smcdonal, stcannon, sthirugn, sthorger, swoodman, szappis, tcunning, teagle, tfister, tom.jenkinson, tqvarnst, vkrizan, vkumar, yfang, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Apache Commons Compress 1.26 Doc Type: If docs needed, set a value
Doc Text:
A loop with an unreachable exit condition (Infinite Loop) vulnerability was found in Apache Common Compress. This issue can lead to a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2264987    

Description Patrick Del Bello 2024-02-19 20:32:14 UTC
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.

Users are recommended to upgrade to version 1.26.0 which fixes the issue.

http://www.openwall.com/lists/oss-security/2024/02/19/1
https://lists.apache.org/thread/cz8qkcwphy4cx8gltn932ln51cbtq6kf

Comment 6 errata-xmlrpc 2024-03-26 11:15:54 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid

Via RHSA-2024:1509 https://access.redhat.com/errata/RHSA-2024:1509

Comment 7 errata-xmlrpc 2024-04-03 10:53:09 UTC
This issue has been addressed in the following products:

  Red Hat build of Quarkus 3.2.11

Via RHSA-2024:1662 https://access.redhat.com/errata/RHSA-2024:1662

Comment 8 errata-xmlrpc 2024-04-18 11:43:59 UTC
This issue has been addressed in the following products:

  Migration Toolkit for Runtimes 1 on RHEL 8

Via RHSA-2024:1924 https://access.redhat.com/errata/RHSA-2024:1924

Comment 9 errata-xmlrpc 2024-04-22 10:59:25 UTC
This issue has been addressed in the following products:

  Red Hat build of Quarkus 2.13.9.SP2

Via RHSA-2024:1797 https://access.redhat.com/errata/RHSA-2024:1797

Comment 17 errata-xmlrpc 2024-05-14 09:08:03 UTC
This issue has been addressed in the following products:

  RHINT Service Registry 2.5.11 GA

Via RHSA-2024:2833 https://access.redhat.com/errata/RHSA-2024:2833

Comment 19 errata-xmlrpc 2024-05-30 20:25:44 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.7.0

Via RHSA-2024:3527 https://access.redhat.com/errata/RHSA-2024:3527

Comment 20 errata-xmlrpc 2024-06-20 00:35:26 UTC
This issue has been addressed in the following products:

  MTA-6.2-RHEL-9
  MTA-6.2-RHEL-8

Via RHSA-2024:3989 https://access.redhat.com/errata/RHSA-2024:3989

Comment 21 errata-xmlrpc 2024-06-24 01:38:32 UTC
This issue has been addressed in the following products:

  RHOSS-1.33-RHEL-8

Via RHSA-2024:4057 https://access.redhat.com/errata/RHSA-2024:4057

Comment 28 errata-xmlrpc 2025-05-14 17:51:20 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.13.0

Via RHSA-2025:7625 https://access.redhat.com/errata/RHSA-2025:7625