Bug 1573045 (CVE-2018-1114) - CVE-2018-1114 undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service
Summary: CVE-2018-1114 undertow: File descriptor leak caused by JarURLConnection.getLa...
Status: NEW
Alias: CVE-2018-1114
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20180421,repor...
Keywords: Security
Depends On: 1573047 1573046 1590658
Blocks: 1571068
TreeView+ depends on / blocked
 
Reported: 2018-04-30 03:09 UTC by Sam Fowler
Modified: 2019-05-07 14:58 UTC (History)
52 users (show)

(edit)
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
Clone Of:
(edit)
Last Closed:


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
JBoss Issue Tracker JBEAP-14672 Major Closed [GSS](7.1.z) CVE-2018-1114 UNDERTOW-1338 - File descriptor leak caused by JarURLConnection.getLastModified() when access... 2019-04-24 08:27 UTC
Red Hat Product Errata RHSA-2018:2643 None None None 2018-09-04 13:45 UTC
Red Hat Knowledge Base (Solution) 3421731 None None None 2018-07-02 02:07 UTC
Red Hat Product Errata RHSA-2018:2669 None None None 2018-09-11 07:55 UTC
Red Hat Product Errata RHSA-2019:0877 None None None 2019-04-24 18:46 UTC
JBoss Issue Tracker UNDERTOW-1338 Major Resolved File descriptor leak cause JarURLConnection.getLastModified() 2019-04-24 08:27 UTC

Description Sam Fowler 2018-04-30 03:09:03 UTC
Undertow has a file handler leak vulnerability caused by JarURLConnection.getLastModified(). A remote attacker could exploit this to cause a denial of service.


External References:

https://issues.jboss.org/browse/UNDERTOW-1338
https://bugs.openjdk.java.net/browse/JDK-6956385

Comment 1 Sam Fowler 2018-04-30 03:09:51 UTC
Created undertow tracking bugs for this issue:

Affects: fedora-all [bug 1573047]

Comment 8 errata-xmlrpc 2018-09-04 13:44:58 UTC
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for Red Hat Enterprise Linux 7

Via RHSA-2018:2643 https://access.redhat.com/errata/RHSA-2018:2643

Comment 9 errata-xmlrpc 2018-09-11 07:55:28 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Fuse

Via RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2018:2669

Comment 14 errata-xmlrpc 2019-04-24 18:46:44 UTC
This issue has been addressed in the following products:

  Red Hat Openshift Application Runtimes

Via RHSA-2019:0877 https://access.redhat.com/errata/RHSA-2019:0877


Note You need to log in before you can comment on or make changes to this bug.