VDB

RHSA-2023:5946

RHSA-2023:5946 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in Netty's SniHandler while navigating TLS handshake which may permit a large heap allocation if the handler did not have a timeout configured. This issue may allow an attacker to send a client hello packet which would cause the server to buffer large amounts of data per connection, potentially causing an out of memory error, resulting in Denial of Service.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red HatRed Hat AMQ Broker 7

Timeline

  • Oct 19, 2023 CVE Published
  • Apr 25, 2026 Security Advisory
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • Aug 7, 2026 CVE Updated
  • Aug 7, 2026 Distribution Patch
  • Aug 7, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›