Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01NjY3LTN3Y2gtN3E3d84AA6V6
Eclipse Vert.x memory leak
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.
Permalink: https://github.com/advisories/GHSA-5667-3wch-7q7wJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NjY3LTN3Y2gtN3E3d84AA6V6
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 8 months ago
Updated: 4 months ago
CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-5667-3wch-7q7w, CVE-2024-1023
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-1023
- https://github.com/eclipse-vertx/vert.x/issues/5078
- https://github.com/eclipse-vertx/vert.x/pull/5080
- https://github.com/eclipse-vertx/vert.x/pull/5082
- https://access.redhat.com/security/cve/CVE-2024-1023
- https://bugzilla.redhat.com/show_bug.cgi?id=2260840
- https://github.com/eclipse-vertx/vert.x/commit/665ceba38444e3929bb7b9a2a0bae2cb603fe81b
- https://github.com/eclipse-vertx/vert.x/commit/dd6f64302b56cd4d3dcf61efaaf174b5f6ce676d
- https://access.redhat.com/errata/RHSA-2024:1662
- https://access.redhat.com/errata/RHSA-2024:1706
- https://access.redhat.com/errata/RHSA-2024:2088
- https://access.redhat.com/errata/RHSA-2024:2833
- https://access.redhat.com/errata/RHSA-2024:3527
- https://access.redhat.com/errata/RHSA-2024:3989
- https://access.redhat.com/errata/RHSA-2024:4884
- https://github.com/advisories/GHSA-5667-3wch-7q7w
Blast Radius: 25.7
Affected Packages
maven:io.vertx:vertx-core
Dependent packages: 1,264Dependent repositories: 8,839
Downloads:
Affected Version Ranges: >= 4.4.5, < 4.4.7, >= 4.5.0, < 4.5.2
Fixed in: 4.4.7, 4.5.2
All affected versions: 4.4.5, 4.4.6, 4.5.0, 4.5.1
All unaffected versions: 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 3.0.0, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.4.0, 3.4.1, 3.4.2, 3.5.0, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0, 3.7.1, 3.8.0, 3.8.1, 3.8.2, 3.8.3, 3.8.4, 3.8.5, 3.9.0, 3.9.1, 3.9.2, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 3.9.8, 3.9.9, 3.9.10, 3.9.11, 3.9.12, 3.9.13, 3.9.14, 3.9.15, 3.9.16, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.1.7, 4.1.8, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5, 4.2.6, 4.2.7, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7, 4.3.8, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.4.4, 4.4.7, 4.4.8, 4.4.9, 4.5.2, 4.5.3, 4.5.4, 4.5.5, 4.5.6, 4.5.7, 4.5.8, 4.5.9, 4.5.10, 4.5.11