Fedora Account System
Red Hat Associate
Red Hat Customer
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption). Upstream Issue: https://bugreports.qt.io/browse/QTBUG-70693 Upstream Fix: https://codereview.qt-project.org/c/qt/qtwebsockets/+/284735
Created qt5-qtwebsockets tracking bugs for this issue: Affects: epel-6 [bug 1810966] Affects: fedora-all [bug 1810965]
Upstream commit for this issue: https://codereview.qt-project.org/gitweb?p=qt%2Fqtwebsockets.git;a=commit;h=ed93680f34e92ad0383aa4e610bb65689118ca93
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-21035
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4690 https://access.redhat.com/errata/RHSA-2020:4690