<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 08:43:21 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-1300 — Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-1300</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; io.vertx:vertx-core, Red Hat CEQ 3.2, Red Hat Cryostat 2 on RHEL 8, Red Hat Migration Toolkit for Runtimes 1 on RHEL 8, Red Hat MTA-6.2-RHEL-9, Red Hat AMQ Streams 2.7.0, Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2, Red Hat build of Quarkus 3.2.11.Final, Red Hat RHINT Service Registry 2.5.11 GA, Red Hat A-MQ Clients 2 and 16 more&lt;/p&gt;
&lt;p&gt;A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; io.vertx:vertx-core, Red Hat CEQ 3.2, Red Hat Cryostat 2 on RHEL 8, Red Hat Migration Toolkit for Runtimes 1 on RHEL 8, Red Hat MTA-6.2-RHEL-9, Red Hat AMQ Streams 2.7.0, Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2, Red Hat build of Quarkus 3.2.11.Final, Red Hat RHINT Service Registry 2.5.11 GA, Red Hat A-MQ Clients 2 and 16 more&lt;/p&gt;
&lt;p&gt;A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-1300</guid>
    </item>
  </channel>
</rss>
