Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:8544 - Bug Fix Advisory
Issued:
2024-10-28
Updated:
2024-10-28

RHBA-2024:8544 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2024:8446 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 2309426 - CVE-2024-6232 python: cpython: tarfile: ReDos via excessive backtracking while parsing header values

CVEs

  • CVE-2024-6232

References

  • https://access.redhat.com/errata/RHSA-2024:8446
  • https://access.redhat.com/containers

aarch64

ubi9/openjdk-11@sha256:7a8c013ea6107756bf79e752a2b0d5703ba956250ca0638cc393737f434f1ddb
ubi9/openjdk-11-runtime@sha256:16c68acad99f0c149b68819a03f4b802274ed9e46a92db82f643fc1580874679
ubi9/openjdk-17@sha256:1235c5208fde90914aea52a8fd874474a0a30e9b2ceff2105359d109643cf12e
ubi9/openjdk-17-runtime@sha256:224db57ab0eeb527119dbe12e6c4e2f790a0a449b5c4ca114b9840c716ef0797
ubi9/openjdk-21@sha256:c9f387b4495cfe517b2680ee5fe14609c55ae68948c4201776e00c323193654e
ubi9/openjdk-21-runtime@sha256:96be9249d2f72699eef9c68735dfbecdd7d007c6485dc3fef157e0ecf3090549

ppc64le

ubi9/openjdk-11@sha256:9793faff1fb9d8bf7535091828baea286d71b1fc58418fa092b8279ac9fee542
ubi9/openjdk-11-runtime@sha256:0433a66d61f4486be26eb2509ec1b7ec847b87a45ab9d6a0cffc9e4e2c359d90
ubi9/openjdk-17@sha256:39567945d9aa1cbc307ccae4e1271078c9fcbfefa7467113286b62ad7fd1a094
ubi9/openjdk-17-runtime@sha256:3d81c54eecc3b01cd220873883cc6c47f42548e73b7db497017ffce90e7d3d72
ubi9/openjdk-21@sha256:4cb7ce379cba458d13f22f35a4e4e418246f58f427387e218c7829358932ba52
ubi9/openjdk-21-runtime@sha256:32b741b7406a052d1c816d82f1ceb8b8882f8e163beb68a8566d9e859deee850

s390x

ubi9/openjdk-11@sha256:13352d909f5f108008001a834afec4782901fb3e12024139f3286fcda421f52a
ubi9/openjdk-11-runtime@sha256:6ecf5b950491a4751a1e3d4285fe450afe27be92c543eb3c385ba3a390d63ca1
ubi9/openjdk-17@sha256:62dfb69b7af0e7012cdf1dbf68011e482e4e40d8a2ba719411c5c8401b365e37
ubi9/openjdk-17-runtime@sha256:7f2acbbf3beebcc9c9a945082c516b2389bbee56def1c5b31f51173be016f5df
ubi9/openjdk-21@sha256:2ceaee27ab74825681f7f77cf3b0f7cf257d8c96638b38554203f67d1cd70d7d
ubi9/openjdk-21-runtime@sha256:1f1f3e0b56e4e19101cf2a75f77d4bd3744684e1e9081b8322d41da1234d7458

x86_64

ubi9/openjdk-11@sha256:050fabd99a73aa5beba0e5dc5a7367dd4563eaf40e4f5ae21a9a345494ad6585
ubi9/openjdk-11-runtime@sha256:c73421cc6ddd21b274d52947be6407deda257113c780e3a645f855a6534268fe
ubi9/openjdk-17@sha256:e09f33aced2b73fa7223675b6999d058840fca8d44c28471c7fea66c979b5542
ubi9/openjdk-17-runtime@sha256:7b25fa1a48c0a5da68aa6aef1a965d1fb70aed73dcba880ce562ddffd8cd476d
ubi9/openjdk-21@sha256:c691d672c41adad5d4f0a2b6f321fa725860c23ca4153fd06508eefffc13a4d2
ubi9/openjdk-21-runtime@sha256:22a449b4b6ce4371e53a7e5e557bdc433b058a888c0378ab185c2e9987214613

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility