CVE-2020-14340

A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
redhatxnio
3.6.1 ≤
𝑥
< 3.7.9
redhatxnio
3.8.0 ≤
𝑥
< 3.8.2
redhatxnio
3.6.0:beta1
redhatxnio
3.6.0:beta2
redhatjboss_data_grid
6.0.0
redhatjboss_data_grid
7.0.0
redhatjboss_data_virtualization
6.0.0
redhatjboss_enterprise_application_platform
5.0.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_fuse
6.0.0
redhatjboss_fuse
7.0.0
redhatjboss_operations_network
3.0
oraclecommunications_cloud_native_core_console
1.9.0
oraclecommunications_cloud_native_core_network_repository_function
1.14.0
oraclecommunications_cloud_native_core_policy
1.14.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy
1.15.0
oraclecommunications_cloud_native_core_service_communication_proxy
1.14.0
oraclecommunications_cloud_native_core_unified_data_repository
1.14.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jboss-xnio
bullseye
3.8.4-1
fixed
buster
no-dsa
stretch
not-affected
bookworm
3.8.8-1
fixed
sid
3.8.10-1
fixed
trixie
3.8.10-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jboss-xnio
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne