The vendor explicitly identifies these products as affected by this CVE.
- netty-codec-redis as a component of Red Hat Fuse 7
- netty-codec-redis as a component of Red Hat JBoss Enterprise Application Platform 7
- netty-codec-redis as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- A flaw was found in netty-codec-redis. A remote attacker can exploit this vulnerability by sending specially crafted Redis payloads across multiple connections without proper termination. This can exhaust the server's direct memory pool, leading to a Denial of Service (DoS) condition where legitimate connections cannot be processed.
- Remediation
- Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
