When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. https://lists.apache.org/thread/q142wj99cwdd0jo5lvdoxzoymlqyjdds https://www.openwall.com/lists/oss-security/2023/09/29/6
This issue has been addressed in the following products: Red Hat Fuse 7.12.1 Via RHSA-2023:7247 https://access.redhat.com/errata/RHSA-2023:7247
This issue has been addressed in the following products: Red Hat build of Quarkus 3.2.9 Via RHSA-2023:7612 https://access.redhat.com/errata/RHSA-2023:7612
This issue has been addressed in the following products: Red Hat Integration Via RHSA-2023:7617 https://access.redhat.com/errata/RHSA-2023:7617
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2023:7639 https://access.redhat.com/errata/RHSA-2023:7639
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2023:7637 https://access.redhat.com/errata/RHSA-2023:7637
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2023:7638 https://access.redhat.com/errata/RHSA-2023:7638
This issue has been addressed in the following products: EAP 7.4.14 Via RHSA-2023:7641 https://access.redhat.com/errata/RHSA-2023:7641
This issue has been addressed in the following products: Red Hat build of Quarkus 2.13.9 Via RHSA-2023:7700 https://access.redhat.com/errata/RHSA-2023:7700
This issue has been addressed in the following products: Red Hat Integration Via RHSA-2023:7705 https://access.redhat.com/errata/RHSA-2023:7705
This issue has been addressed in the following products: Red Hat Fuse 7.13.0 Via RHSA-2024:3354 https://access.redhat.com/errata/RHSA-2024:3354
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Via RHSA-2024:10208 https://access.redhat.com/errata/RHSA-2024:10208
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Via RHSA-2024:10207 https://access.redhat.com/errata/RHSA-2024:10207