CVE-2024-3653: Missing Release of Memory after Effective Lifetime in Red Hat Red Hat build of Quarkus 3.8.6.redhat
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
AI Analysis
Technical Summary
CVE-2024-3653 is a vulnerability in the Undertow web server component used by Red Hat JBoss Enterprise Application Platform. The flaw occurs when the learning-push handler is enabled without configuring the maxAge parameter, which defaults to -1, resulting in a condition where memory is not released after its effective lifetime. This can be exploited remotely by an attacker sending standard HTTP requests, leading to a denial of service via memory exhaustion. The vulnerability is not present if the maxAge configuration is overwritten from its default. Red Hat has issued security advisories and patches for affected versions of JBoss Enterprise Application Platform 7.4 and 8.0 to remediate this issue.
Potential Impact
The vulnerability allows a remote attacker to cause a denial of service by exhausting server memory due to the learning-push handler not releasing memory properly when maxAge is set to its default of -1. There is no impact on confidentiality or integrity. The attack requires no privileges and no user interaction beyond sending normal HTTP requests to the server with the vulnerable handler enabled and unconfigured. This can degrade or disrupt service availability.
Mitigation Recommendations
Red Hat has released official security updates for Red Hat JBoss Enterprise Application Platform versions 7.4 and 8.0 that address this vulnerability. Applying these updates will remediate the issue. Alternatively, disabling the learning-push handler or explicitly configuring the maxAge parameter to a non-default value will prevent exploitation. Users should follow Red Hat's guidance and apply the relevant errata updates as detailed in the vendor advisories. Patch status is confirmed as fixed in these updates.
CVE-2024-3653: Missing Release of Memory after Effective Lifetime in Red Hat Red Hat build of Quarkus 3.8.6.redhat
Description
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
CVSS v3.1
Score 5.3medium
Affected software
Red Hat
Red Hat build of Quarkus 3.8.6.redhat
Red Hat
Red Hat JBoss Enterprise Application Platform
Red Hat
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
Red Hat
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
Red Hat
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
Red Hat
Red Hat JBoss Enterprise Application Platform 8
Red Hat
OpenShift Serverless
Red Hat
Red Hat build of Apache Camel 4 for Quarkus 3
Red Hat
Red Hat build of Apache Camel for Spring Boot 4
Red Hat
Red Hat build of Apache Camel - HawtIO 4
Red Hat
Red Hat build of Apicurio Registry 2
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat build of OptaPlanner 8
Red Hat
Red Hat build of Quarkus
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat Fuse 7
Red Hat
Red Hat Integration Camel K 1
Red Hat
Red Hat Integration Camel Quarkus 2
Red Hat
Red Hat JBoss Data Grid 7
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat JBoss Fuse Service Works 6
Red Hat
Red Hat Process Automation 7
Red Hat
Red Hat Single Sign-On 7
Red Hat
streams for Apache Kafka
pkg:maven/io.undertow/undertow-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-3653 is a vulnerability in the Undertow web server component used by Red Hat JBoss Enterprise Application Platform. The flaw occurs when the learning-push handler is enabled without configuring the maxAge parameter, which defaults to -1, resulting in a condition where memory is not released after its effective lifetime. This can be exploited remotely by an attacker sending standard HTTP requests, leading to a denial of service via memory exhaustion. The vulnerability is not present if the maxAge configuration is overwritten from its default. Red Hat has issued security advisories and patches for affected versions of JBoss Enterprise Application Platform 7.4 and 8.0 to remediate this issue.
Potential Impact
The vulnerability allows a remote attacker to cause a denial of service by exhausting server memory due to the learning-push handler not releasing memory properly when maxAge is set to its default of -1. There is no impact on confidentiality or integrity. The attack requires no privileges and no user interaction beyond sending normal HTTP requests to the server with the vulnerable handler enabled and unconfigured. This can degrade or disrupt service availability.
Mitigation Recommendations
Red Hat has released official security updates for Red Hat JBoss Enterprise Application Platform versions 7.4 and 8.0 that address this vulnerability. Applying these updates will remediate the issue. Alternatively, disabling the learning-push handler or explicitly configuring the maxAge parameter to a non-default value will prevent exploitation. Users should follow Red Hat's guidance and apply the relevant errata updates as detailed in the vendor advisories. Patch status is confirmed as fixed in these updates.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2024-04-11T04:14:52.345Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2024:4392","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5143","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5144","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5145","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5147","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:6437","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-3653","vendor":"Red Hat"}]
Threat ID: 68faafd950358b89bd7bfd3a
Added to database: 10/23/2025, 22:44:41 UTC
Last enriched: 08/05/2026, 13:15:20 UTC
Last updated: 09/10/2026, 19:46:20 UTC
Views: 399
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.