The vendor explicitly identifies these products as affected by this CVE.
- lz4-java as a component of Logging Subsystem for Red Hat OpenShift
- lz4-java as a component of Red Hat build of Apache Camel - HawtIO 4
- lz4-java as a component of Red Hat build of Apache Camel 4 for Quarkus 3
- lz4-java as a component of Red Hat build of Apicurio Registry 2
- lz4-java as a component of Red Hat build of Apicurio Registry 3
- lz4-java as a component of Red Hat build of Debezium 2
- lz4-java as a component of Red Hat build of Debezium 3
- lz4-java as a component of Red Hat Enterprise Linux 8
- lz4-java-javadoc as a component of Red Hat Enterprise Linux 8
- lz4-java as a component of Red Hat Fuse 7
- lz4-java as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- lz4-java as a component of Red Hat Process Automation 7
- Summary
- A flaw was found in lz4-java. This vulnerability allows disclosure of sensitive data via crafted compressed input due to insufficient clearing of the output buffer in Java-based decompressor implementations.
- Remediation
- Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
