The vendor explicitly identifies these products or versions as containing the fix.
- perl-thrift-0:0.24.0-1.el9ai.noarch as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- python3-thrift-debuginfo-0:0.24.0-1.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- thrift-0:0.24.0-1.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- thrift-0:0.24.0-1.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- thrift-0:0.24.0-1.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
- Summary
- A flaw was found in Apache Thrift C++ bindings. A remote, unauthenticated attacker can exploit a heap-based buffer overflow vulnerability without user interaction. This can lead to arbitrary code execution, allowing the attacker to gain full control over the affected system, compromise data, and cause a denial of service.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
