It was found that JSS did not properly free up all the memory resulting of a TLS connection. This could be used by an attacker to force the invocation of Linux's Out-Of-Memory process, causing a denial of service.
Created jss tracking bugs for this issue: Affects: fedora-all [bug 2052632]
Upstream fix : https://github.com/dogtagpki/jss/commit/5922560a78d0dee61af8a33cc9cfbf4cfa291448 https://github.com/dogtagpki/jss/commit/3aabe0e9d59b0a42e68ac8cd0468f9c5179967d2
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1851 https://access.redhat.com/errata/RHSA-2022:1851
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-4213
*** Bug 2011102 has been marked as a duplicate of this bug. ***