Bug 2306158 (CVE-2024-6119)
Summary: | CVE-2024-6119 openssl: Possible denial of service in X.509 name checks | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Patrick Del Bello <pdelbell> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | akostadi, amasferr, asdas, bmontgom, cbartlet, chazlett, csutherl, dbosanac, dmayorov, doconnor, dpaolell, eparis, jburrell, jcantril, jclere, jdelft, jlledo, jreimann, jupierce, lgarciaa, mbenatto, mbiarnes, mdessi, mjaros, mkudlej, mlewando, mmakovy, mrezanin, mrizzi, nstielau, nyancey, pcattana, pjanda, pjindal, pjones, plodge, raravind, security-response-team, sidsharm, sponnaga, szappis, talessio, teagle, tjochec, vlaad, ximhan, yuxzhu |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A flaw was found in OpenSSL. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Deadline: | 2024-09-04 |
Description
Patrick Del Bello
2024-08-20 17:55:58 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:6783 https://access.redhat.com/errata/RHSA-2024:6783 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2024:7599 https://access.redhat.com/errata/RHSA-2024:7599 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:8935 https://access.redhat.com/errata/RHSA-2024:8935 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2024:10818 https://access.redhat.com/errata/RHSA-2024:10818 |