The vendor explicitly identifies these products or versions as containing the fix.
- rabbitmq-server4-2-main@aarch64 as a component of Red Hat Hardened Images
- rabbitmq-server4-2-main@src as a component of Red Hat Hardened Images
- rabbitmq-server4-2-main@x86_64 as a component of Red Hat Hardened Images
- rabbitmq-server4-3-main@aarch64 as a component of Red Hat Hardened Images
- rabbitmq-server4-3-main@src as a component of Red Hat Hardened Images
- rabbitmq-server4-3-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in Cowboy. An unauthenticated remote attacker can exploit this vulnerability by sending multiple HTTP/1.1 header lines with the same name. This bypasses the `max_headers` limit, causing the connection process memory to grow uncontrollably. This can lead to memory exhaustion and a Denial of Service (DoS) condition in the Erlang Virtual Machine (VM).
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
