Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1573391 - (CVE-2018-10237) CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service
CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and Co...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180425,repor...
: Security
Depends On: 1573393 1576452 1592469 1592470 1592471 1592472 1573394 1573494 1573498 1573499 1574786 1576453 1582987 1582988 1582989 1582990 1582991 1582992 1582993 1591096
Blocks: 1573396
  Show dependency treegraph
 
Reported: 2018-05-01 00:06 EDT by Sam Fowler
Modified: 2018-10-19 17:48 EDT (History)
117 users (show)

See Also:
Fixed In Version: guava 24.1.1, guava 25.0
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in Guava where the AtomicDoubleArray and CompoundOrdering classes were found to allocate memory based on size fields sent by the client without validation. A crafted message could cause the server to consume all available memory or crash leading to a denial of service.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2423 None None None 2018-08-15 07:31 EDT
Red Hat Product Errata RHSA-2018:2424 None None None 2018-08-15 07:33 EDT
Red Hat Product Errata RHSA-2018:2425 None None None 2018-08-15 07:20 EDT
Red Hat Product Errata RHSA-2018:2428 None None None 2018-08-15 07:30 EDT
Red Hat Product Errata RHSA-2018:2598 None None None 2018-08-29 12:20 EDT
Red Hat Product Errata RHSA-2018:2643 None None None 2018-09-04 09:45 EDT
Red Hat Product Errata RHSA-2018:2740 None None None 2018-09-24 17:47 EDT
Red Hat Product Errata RHSA-2018:2741 None None None 2018-09-24 18:04 EDT
Red Hat Product Errata RHSA-2018:2742 None None None 2018-09-24 18:08 EDT
Red Hat Product Errata RHSA-2018:2743 None None None 2018-09-24 18:10 EDT
Red Hat Product Errata RHSA-2018:2927 None None None 2018-10-16 11:23 EDT

  None (edit)
Description Sam Fowler 2018-05-01 00:06:46 EDT
Google Guava versions 11.0 through 24.1 are vulnerable to unbounded memory allocation in the AtomicDoubleArray class (when serialized with Java serialization) and Compound Ordering class (when serialized with GWT serialization). An attacker could exploit applications that use Guava and deserialize untrusted data to cause a denial of service.


External References:

https://github.com/google/guava/wiki/CVE-2018-10237
https://groups.google.com/forum/#!topic/guava-announce/xqWALw4W1vs/discussion


Upstream Patch:

https://github.com/google/guava/commit/7ec8718f1e6e2814dabaa4b9f96b6b33a813101c
Comment 1 Sam Fowler 2018-05-01 00:08:15 EDT
Created guava tracking bugs for this issue:

Affects: fedora-all [bug 1573394]
Comment 4 Michael Simacek 2018-05-02 09:14:43 EDT
Note there is guava20 compat package as well.
Comment 5 Sam Fowler 2018-05-03 23:40:19 EDT
Created guava20 tracking bugs for this issue:

Affects: fedora-28 [bug 1574786]
Comment 13 Scott Gayou 2018-06-18 12:02:17 EDT
Statement:

Red Hat Product Security has rated this issue as having a security impact of Moderate, and a future update may address this flaw.
Comment 17 errata-xmlrpc 2018-08-15 07:20:17 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:2425 https://access.redhat.com/errata/RHSA-2018:2425
Comment 18 errata-xmlrpc 2018-08-15 07:29:39 EDT
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.2.4 zip

Via RHSA-2018:2428 https://access.redhat.com/errata/RHSA-2018:2428
Comment 19 errata-xmlrpc 2018-08-15 07:30:45 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2018:2423 https://access.redhat.com/errata/RHSA-2018:2423
Comment 20 errata-xmlrpc 2018-08-15 07:32:34 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2018:2424 https://access.redhat.com/errata/RHSA-2018:2424
Comment 21 errata-xmlrpc 2018-08-29 12:20:15 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 13.0 (Queens)

Via RHSA-2018:2598 https://access.redhat.com/errata/RHSA-2018:2598
Comment 23 errata-xmlrpc 2018-09-04 09:44:59 EDT
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for Red Hat Enterprise Linux 7

Via RHSA-2018:2643 https://access.redhat.com/errata/RHSA-2018:2643
Comment 24 errata-xmlrpc 2018-09-24 17:46:30 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:2740 https://access.redhat.com/errata/RHSA-2018:2740
Comment 25 errata-xmlrpc 2018-09-24 18:04:21 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2018:2741 https://access.redhat.com/errata/RHSA-2018:2741
Comment 26 errata-xmlrpc 2018-09-24 18:08:15 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5

Via RHSA-2018:2742 https://access.redhat.com/errata/RHSA-2018:2742
Comment 27 errata-xmlrpc 2018-09-24 18:09:37 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2018:2743 https://access.redhat.com/errata/RHSA-2018:2743
Comment 29 errata-xmlrpc 2018-10-16 11:22:28 EDT
This issue has been addressed in the following products:

  Red Hat Satellite 6.4 for RHEL 7

Via RHSA-2018:2927 https://access.redhat.com/errata/RHSA-2018:2927

Note You need to log in before you can comment on or make changes to this bug.