CVE-2024-8447

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
Configurations

No configuration.

History

14 May 2025, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:7620 -

27 Mar 2025, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3357 -

27 Mar 2025, 18:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3358 -
Summary
  • (es) Se descubrió un problema de seguridad en LRA Coordinator component de Narayana. Cuando se llama a Cancel en LRA, se produce un tiempo de ejecución de aproximadamente 2 segundos. Si se llama a Join con el mismo ID de LRA dentro de ese período de tiempo, la aplicación puede bloquearse o bloquearse indefinidamente, lo que genera una denegación de servicio.

02 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-02 21:15

Updated : 2025-05-14 23:15


NVD link : CVE-2024-8447

Mitre link : CVE-2024-8447

CVE.ORG link : CVE-2024-8447


JSON object : View

Products Affected

No product.

CWE
CWE-833

Deadlock