Bug 2315730 (CVE-2024-43483)

Summary: CVE-2024-43483 dotnet: Multiple .NET components susceptible to hash flooding
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in dotnet. The System.Security.Cryptography.Cose, System.IO.Packaging and System.Runtime.Caching components may be exposed to hostile input, making them susceptible to hash flooding attacks, resulting in denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2317291, 2317332, 2317334, 2317337, 2317339    
Bug Blocks:    
Deadline: 2024-10-08   

Description OSIDB Bzimport 2024-09-30 18:25:40 UTC
A Denial of Service flaw was found in Multiple .NET components susceptible to hash flooding.

Comment 1 errata-xmlrpc 2024-10-09 11:41:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:7851 https://access.redhat.com/errata/RHSA-2024:7851

Comment 2 errata-xmlrpc 2024-10-09 14:27:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:7867 https://access.redhat.com/errata/RHSA-2024:7867

Comment 3 errata-xmlrpc 2024-10-09 14:42:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:7868 https://access.redhat.com/errata/RHSA-2024:7868

Comment 4 errata-xmlrpc 2024-10-09 14:58:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:7869 https://access.redhat.com/errata/RHSA-2024:7869

Comment 5 errata-xmlrpc 2024-10-14 02:28:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:8036 https://access.redhat.com/errata/RHSA-2024:8036

Comment 6 errata-xmlrpc 2024-10-14 11:11:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2024:8048 https://access.redhat.com/errata/RHSA-2024:8048

Comment 7 errata-xmlrpc 2024-10-14 11:17:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:8047 https://access.redhat.com/errata/RHSA-2024:8047

Comment 8 errata-xmlrpc 2024-10-14 18:21:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

Via RHSA-2024:8082 https://access.redhat.com/errata/RHSA-2024:8082