CVE-2024-8447
Executive Summary
A timing flaw in Narayana’s LRA Coordinator causes a denial‑of‑service when a Cancel is followed by a Join with the same LRA ID within ~2 seconds. The application may crash or hang indefinitely, disrupting transaction processing.
Authoritative CVE Metadata - CVSS Base Score: 5.9 (MEDIUM) - Published: 2025-01-02T21:15:10.303 - Last Modified: 2026-09-07T15:17:29.960
Original Description: A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.
"Sooner or later, those who win are those who think they can."
— Richard Bach