-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Low: Red Hat AMQ Broker 7.9.1 release and security update Advisory ID: RHSA-2021:4851-01 Product: Red Hat JBoss AMQ Advisory URL: https://access.redhat.com/errata/RHSA-2021:4851 Issue date: 2021-11-30 Keywords: amq,messaging,integration,broker CVE Names: CVE-2021-37136 CVE-2021-37137 ===================================================================== 1. Summary: Red Hat AMQ Broker 7.9.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. This release of Red Hat AMQ Broker 7.9.1 serves as a replacement for Red Hat AMQ Broker 7.9.0, and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data (CVE-2021-37136) * netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way (CVE-2021-37137) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 2004133 - CVE-2021-37136 netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data 2004135 - CVE-2021-37137 netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way 5. References: https://access.redhat.com/security/cve/CVE-2021-37136 https://access.redhat.com/security/cve/CVE-2021-37137 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.9.1 https://access.redhat.com/documentation/en-us/red_hat_amq/2021.q4 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYaY4ONzjgjWX9erEAQjwTQ/+KvM3XfnqjXhDVOI0kOxvqXFsIdvxXL6v u6Og2TDZEKMjq3RYraBPFF8GPdARK2hACNS7dgnoD2uGgpIyeqWLN3lHv+kUUS0W I6fKcbC0rnEfRWTUoCRZ7jY9DQiJzOVyfAe1SgTv6csrzhEGTJRhMR05kE4yr3Aa YXt/oXcjgOVw3QoxZ/RY7YFOOwXH4OIx9iMn0t/vITwzba92PoUHYWfvkaHqSyxU 3p1bk1Y+5fW8neS6WCapgYMGgf/KoA0YJNF5L6GEPaBfPfQWb7qmGcZCyTpVvRJI 6lwjgbun+u2bzQYXKoD96kDvJ7j+DI+JTdLE3ZymU5vZKOarHnGhrrZUnFaieR4G fj/v5p3YRvpoE5Xv43CLX3DoBBvA8awyQSgz0AC/YkvAn7webYiCnbOlaQluMnMC dApR4oJjkB7zVmnnG2r4OLHdmPwsUGHvlGQNwRx5h7u0ghZfumUwyLMaudBvAKx3 hZbN4b6RgJLEeGI/8L823iWQs82vL5b0EP1EEYKrwenK4kTQdJtLgbXy1Wnz89sQ PGLEqhWQ+R3SuEwZQt2U0CtGVkm5FUCrHlhfPYSpXxNwESKSPgKLajpiW4IgoiF9 CvRXH9Jz8WLANcQKiqbvRLXav1t9/0JyB/3bl+xWt93LtLb4doo1/aiRZSrpfc57 bxbuWYV2WT4= =Vz1/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce