The vendor explicitly identifies these products as affected by this CVE.
- bcprov-jdk15on as a component of Red Hat AMQ Clients
- resteasy-javadoc (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy-javadoc (pki-deps:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy.src (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy.src (pki-deps:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy (pki-core:10.6) as a component of Red Hat Enterprise Linux 8
- resteasy (pki-deps:10.6) as a component of Red Hat Enterprise Linux 8
- pki-resteasy as a component of Red Hat Enterprise Linux 9
- pki-resteasy-client as a component of Red Hat Enterprise Linux 9
- pki-resteasy-core as a component of Red Hat Enterprise Linux 9
- pki-resteasy-jackson2-provider as a component of Red Hat Enterprise Linux 9
- pki-resteasy-servlet-initializer as a component of Red Hat Enterprise Linux 9
- Summary
- A flaw was found in Bouncy Castle for Java. A remote attacker could exploit this vulnerability by providing a specially crafted self-referential IEEE 1609.2 schema to the OER (Octet Encoding Rules) parser. This can cause the parser to recurse without a depth limit, leading to resource exhaustion and a denial of service (DoS) for the affected system.
- Remediation
- Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcutil-fips 2.0.7/2.1.7) once available for the affected product.
