The vendor explicitly identifies these products as affected by this CVE.
- quarkus-websockets-next-spi as a component of Red Hat Build of Keycloak
- rhceph/rhceph-5-dashboard-rhel8 as a component of Red Hat Ceph Storage 5
- rhceph/rhceph-6-dashboard-rhel9 as a component of Red Hat Ceph Storage 6
- rhceph/grafana-rhel9 as a component of Red Hat Ceph Storage 7
- rhceph/grafana-rhel9 as a component of Red Hat Ceph Storage 8
- rhceph/alloy-rhel10 as a component of Red Hat Ceph Storage 9
- rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-gaudi-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/disk-image-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- process-nextick-args as a component of Red Hat JBoss Enterprise Application Platform 7
- process-nextick-args as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Next.js, a React framework for building web applications. A remote attacker can send specially crafted requests to Next.js applications that utilize the App Router with Server Actions. This can lead to excessive CPU usage, causing the application to become unresponsive and preventing it from processing further requests, resulting in a Denial of Service (DoS).
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
