The vendor explicitly identifies these products as affected by this CVE.
- openshift-sandboxed-containers/osc-podvm-payload-rhel9 as a component of Confidential Compute Attestation
- thrift.src as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- kata-containers as a component of Red Hat OpenShift Container Platform 4
- kata-containers.src as a component of Red Hat OpenShift Container Platform 4
- openshift-update-service/openshift-update-service-rhel8 as a component of Red Hat OpenShift Update Service
- Summary
- A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can trigger a continuous loop, leading to a denial of service (DoS) for applications using the affected bindings.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
