• CVE-2024-8447

发布时间: 2025年1月3日

修改时间: 2025年4月2日

概要

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

CVSS v3 指标

NVD openEuler
Confidentiality None None
Attack Vector Network Network
CVSS评分 N/A 5.9
Attack Complexity High High
Privileges Required None None
Scope Unchanged Unchanged
Integrity None None
User Interaction None None
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-1004 A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service. 2025年1月15日

影响产品

产品 状态
KY3.4-5 narayana Unaffected
KY3.5.2 narayana Unaffected
KY3.5.3 narayana Unaffected
V6 narayana Unaffected