CVE-2022-2529: Uncontrolled Resource Consumption
(updated )
sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.
References
- github.com/advisories/GHSA-9rpw-2h95-666c
- github.com/cloudflare/goflow/commit/2b94619a6204443e3ca1769f4e459f9f57039c51
- github.com/cloudflare/goflow/commit/c829ccd2c0aafdc9b886b20bf6f28095607f4998
- github.com/cloudflare/goflow/releases/tag/v3.4.4
- github.com/cloudflare/goflow/security/advisories/GHSA-9rpw-2h95-666c
- nvd.nist.gov/vuln/detail/CVE-2022-2529
Detect and mitigate CVE-2022-2529 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →