A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:21399 https://access.redhat.com/errata/RHSA-2025:21399
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2025:21402 https://access.redhat.com/errata/RHSA-2025:21402
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:21401 https://access.redhat.com/errata/RHSA-2025:21401
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:21404 https://access.redhat.com/errata/RHSA-2025:21404
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:21405 https://access.redhat.com/errata/RHSA-2025:21405
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:21400 https://access.redhat.com/errata/RHSA-2025:21400
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:21406 https://access.redhat.com/errata/RHSA-2025:21406
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:21403 https://access.redhat.com/errata/RHSA-2025:21403
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:21452 https://access.redhat.com/errata/RHSA-2025:21452
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:21462 https://access.redhat.com/errata/RHSA-2025:21462
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:21628 https://access.redhat.com/errata/RHSA-2025:21628