An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack. https://github.com/sindresorhus/file-type/releases/tag/v16.5.4 https://github.com/sindresorhus/file-type/releases/tag/v17.1.3 https://www.npmjs.com/package/file-type https://security.netapp.com/advisory/ntap-20220909-0005/
Created yarnpkg tracking bugs for this issue: Affects: fedora-all [bug 2159683]
This issue has been addressed in the following products: Red Hat Data Grid 8.4.1 Via RHSA-2023:0713 https://access.redhat.com/errata/RHSA-2023:0713
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-36313