Fedora Account System
Red Hat Associate
Red Hat Customer
Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.
Created rubygem-rack tracking bugs for this issue: Affects: epel-8 [bug 2164720] Affects: fedora-all [bug 2164721]
This issue has been addressed in the following products: Red Hat Satellite 6.14 for RHEL 8 Via RHSA-2023:6818 https://access.redhat.com/errata/RHSA-2023:6818