The vendor explicitly identifies these products as affected by this CVE.
- jackson-dataformat-cbor as a component of Red Hat Integration Camel Quarkus 1
- jackson-dataformat-cbor as a component of Red Hat OpenShift Application Runtimes
- openshift3/ose-logging-elasticsearch5 as a component of Red Hat OpenShift Container Platform 3.11
- openshift4/ose-logging-elasticsearch6 as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-metering-hadoop as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-metering-hive as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-metering-presto as a component of Red Hat OpenShift Container Platform 4
- Summary
- This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
