vulnerability
Red Hat JBoss EAP: CVE-2018-1041: Infinite Loop
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Feb 5, 2018 | Sep 19, 2024 | Jul 2, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Feb 5, 2018
Added
Sep 19, 2024
Modified
Jul 2, 2025
Description
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.. A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10.Final-redhat-1, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.
Solution
red-hat-jboss-eap-upgrade-latest
References
- CWE-835
- CVE-2018-1041
- https://attackerkb.com/topics/CVE-2018-1041
- URL-https://access.redhat.com/security/cve/CVE-2018-1041
- URL-https://bugzilla.redhat.com/show_bug.cgi?id=1530457
- URL-https://access.redhat.com/errata/RHSA-2018:0268
- URL-https://access.redhat.com/errata/RHSA-2018:0269
- URL-https://access.redhat.com/errata/RHSA-2018:0270
- URL-https://access.redhat.com/errata/RHSA-2018:0271
- URL-https://access.redhat.com/errata/RHSA-2018:0275
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.