The vendor explicitly identifies these products or versions as containing the fix.
- nats-server2-12-main@aarch64 as a component of Red Hat Hardened Images
- nats-server2-12-main@src as a component of Red Hat Hardened Images
- nats-server2-12-main@x86_64 as a component of Red Hat Hardened Images
- nats-server2-14-main@aarch64 as a component of Red Hat Hardened Images
- nats-server2-14-main@src as a component of Red Hat Hardened Images
- nats-server2-14-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in NATS Server. An unauthenticated remote attacker could send large, incomplete MQTT CONNECT packets to the server. This action causes the server to retain these packets, consuming significant memory before authentication is complete. This can lead to a denial of service (DoS) condition, making the server unavailable to legitimate users.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
