Narayana deadlock via multiple join requests sent to LRA Coordinator
Moderate severity
GitHub Reviewed
Published
Jan 2, 2025
to the GitHub Advisory Database
•
Updated Jan 2, 2025
Package
Affected versions
< 7.1.0.Final
Patched versions
7.1.0.Final
Description
Published by the National Vulnerability Database
Jan 2, 2025
Published to the GitHub Advisory Database
Jan 2, 2025
Reviewed
Jan 2, 2025
Last updated
Jan 2, 2025
A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
References