Skip to main content
EPSS 1.9%top 22%

CVE-2024-3653: Missing Release of Memory after Effective Lifetime in Red Hat Red Hat build of Quarkus 3.8.6.redhat

0
Medium
VulnerabilityCVE-2024-3653cvecve-2024-3653
Published: 07/08/2024 (07/08/2024, 21:21:20 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat build of Quarkus 3.8.6.redhat

Description

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected software

Red Hat

Red Hat build of Quarkus 3.8.6.redhat

Red Hat

Red Hat JBoss Enterprise Application Platform

Red Hat

Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8

Red Hat

Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9

Red Hat

Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7

Red Hat

Red Hat JBoss Enterprise Application Platform 8

Red Hat

OpenShift Serverless

Red Hat

Red Hat build of Apache Camel 4 for Quarkus 3

Red Hat

Red Hat build of Apache Camel for Spring Boot 4

Red Hat

Red Hat build of Apache Camel - HawtIO 4

Red Hat

Red Hat build of Apicurio Registry 2

Red Hat

Red Hat Build of Keycloak

Red Hat

Red Hat build of OptaPlanner 8

Red Hat

Red Hat build of Quarkus

Red Hat

Red Hat Data Grid 8

Red Hat

Red Hat Fuse 7

Red Hat

Red Hat Integration Camel K 1

Red Hat

Red Hat Integration Camel Quarkus 2

Red Hat

Red Hat JBoss Data Grid 7

Red Hat

Red Hat JBoss Enterprise Application Platform Expansion Pack

Red Hat

Red Hat JBoss Fuse Service Works 6

Red Hat

Red Hat Process Automation 7

Red Hat

Red Hat Single Sign-On 7

Red Hat

streams for Apache Kafka

io.undertow/undertow-core
pkg:maven/io.undertow/undertow-core
Affected versions
=0
GitHub Actionsmore threats →cve
undertow
pkg:github/undertow
Affected versions
>=0 <=2.3.14.Final

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 13:15:20 UTC

Technical Analysis

CVE-2024-3653 is a vulnerability in the Undertow web server component used by Red Hat JBoss Enterprise Application Platform. The flaw occurs when the learning-push handler is enabled without configuring the maxAge parameter, which defaults to -1, resulting in a condition where memory is not released after its effective lifetime. This can be exploited remotely by an attacker sending standard HTTP requests, leading to a denial of service via memory exhaustion. The vulnerability is not present if the maxAge configuration is overwritten from its default. Red Hat has issued security advisories and patches for affected versions of JBoss Enterprise Application Platform 7.4 and 8.0 to remediate this issue.

Potential Impact

The vulnerability allows a remote attacker to cause a denial of service by exhausting server memory due to the learning-push handler not releasing memory properly when maxAge is set to its default of -1. There is no impact on confidentiality or integrity. The attack requires no privileges and no user interaction beyond sending normal HTTP requests to the server with the vulnerable handler enabled and unconfigured. This can degrade or disrupt service availability.

Mitigation Recommendations

Red Hat has released official security updates for Red Hat JBoss Enterprise Application Platform versions 7.4 and 8.0 that address this vulnerability. Applying these updates will remediate the issue. Alternatively, disabling the learning-push handler or explicitly configuring the maxAge parameter to a non-default value will prevent exploitation. Users should follow Red Hat's guidance and apply the relevant errata updates as detailed in the vendor advisories. Patch status is confirmed as fixed in these updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
redhat
Date Reserved
2024-04-11T04:14:52.345Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/errata/RHSA-2024:4392","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5143","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5144","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5145","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5147","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:6437","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-3653","vendor":"Red Hat"}]

Threat ID: 68faafd950358b89bd7bfd3a

Added to database: 10/23/2025, 22:44:41 UTC

Last enriched: 08/05/2026, 13:15:20 UTC

Last updated: 09/10/2026, 19:46:20 UTC

Views: 399

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses