The vendor explicitly identifies these products as affected by this CVE.
- org.jboss.narayana-narayana-all as a component of Red Hat JBoss Data Grid 7
- org.jboss.narayana-narayana-all as a component of Red Hat JBoss Enterprise Application Platform 7
- org.jboss.narayana-narayana-all as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
- Remediation
- Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
