Red Hat Security Advisory: Red Hat Integration Camel K 1.10.9 release and security update.
🔗 CVE IDs covered (5)
📋 Description
CVE-2019-12900 — bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail). CVE-2024-20954 — graalvm: Unauthorized Read Access CVE-2024-21098 — graalvm: unauthorized ability to cause a partial denial of service CVE-2024-52531 — libsoup: buffer overflow via UTF-8 conversion in soup_header_parse_param_list_strict CVE-2025-21502 — openjdk: Enhance array handling (Oracle CPU 2025-01)
🎯 Affected products1
- RHINT Camel-K 1.10.9
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No current mitigation is available for this vulnerability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:1154
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278636
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278674
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2325277
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2332075
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2338992
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1154.json