The vendor explicitly identifies these products as affected by this CVE.
- erlang-asn1 as a component of Red Hat OpenStack Platform 16.2
- erlang-compiler as a component of Red Hat OpenStack Platform 16.2
- erlang-crypto as a component of Red Hat OpenStack Platform 16.2
- erlang-eldap as a component of Red Hat OpenStack Platform 16.2
- erlang-erts as a component of Red Hat OpenStack Platform 16.2
- erlang-hipe as a component of Red Hat OpenStack Platform 16.2
- erlang-inets as a component of Red Hat OpenStack Platform 16.2
- erlang-kernel as a component of Red Hat OpenStack Platform 16.2
- erlang-mnesia as a component of Red Hat OpenStack Platform 16.2
- erlang-os_mon as a component of Red Hat OpenStack Platform 16.2
- erlang-parsetools as a component of Red Hat OpenStack Platform 16.2
- erlang-public_key as a component of Red Hat OpenStack Platform 16.2
- Summary
- A flaw was found in Erlang/OTP's SSL (Secure Sockets Layer) application. An unauthenticated remote attacker can send a specially crafted ClientHello message to a TLS 1.3 server with session tickets enabled. This can permanently disrupt the server's ability to handle session tickets, leading to a Denial of Service (DoS) for new TLS 1.3 connections until the SSL application is restarted. This vulnerability is caused by improper validation of PSK (Pre-Shared Key) identity and binder list lengths.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
