Impact
A flaw exists in the Cockpit management interface that allows an unauthenticated remote attacker to establish and maintain an arbitrary number of concurrent connections to the cockpit‑tls service. Each connection spawns a detached thread in the service, exhausting memory and file descriptor resources. The result is a denial of service, causing the Cockpit interface to become unresponsive or unavailable for legitimate users. This weakness is categorized as CWE‑770: Uncontrolled Resource Consumption.
Affected Systems
Red Hat Enterprise Linux releases 7, 8, 9, 10 and Red Hat OpenShift Dev Spaces include the vulnerable Cockpit component. The CVE does not specify affected Cockpit versions, but any installation of Cockpit embedded in those product lines remains susceptible until patched.
Risk and Exploitability
The vulnerability scores a CVSS of 7.5, indicating high risk when exploited. No EPSS score is currently available, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker with network access to the cockpit‑tls port can trigger the issue by flooding the service with connections; the required privilege level is none, as the exploitation is unauthenticated. The lack of a developed exploit in the public domain limits immediate threat, yet the high impact and unrestricted remote access reflect a notable risk for exposed systems.
OpenCVE Enrichment