CVE-2020-14340

Severity
5.9MEDIUM
EPSS
0.3%
top 44.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateApr 15

Description

A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages17 packages

NVDredhat/xnio3.6.13.7.9+2
Mavenorg.jboss.xnio:xnio-nio3.8.0.Final3.8.2.Final+1
Debianjboss-xnio< 3.8.2-1+3
CVEListV5xnioxnio 3.7.9.Final, xnio 3.8.2.Final, xnio 3.9.0.Final

Patches

🔴Vulnerability Details

4
OSV
Uncontrolled Resource Consumption in XNIO2021-06-08
GHSA
Uncontrolled Resource Consumption in XNIO2021-06-08
OSV
CVE-2020-14340: A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cy2021-06-02
CVEList
CVE-2020-14340: A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cy2021-06-02

📋Vendor Advisories

4
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (XNIO) — CVE-2020-143402022-04-15
Oracle
Oracle Oracle Communications Risk Matrix: Network Repository Function (XNIO) — CVE-2020-143402022-01-15
Red Hat
xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS2020-07-24
Debian
CVE-2020-14340: jboss-xnio - A vulnerability was discovered in XNIO where file descriptor leak caused by grow...2020

💬Community

2
Bugzilla
CVE-2020-14340 xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS2020-07-24
Bugzilla
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)2018-07-23