CVE Vulnerabilities

CVE-2022-0711

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 02, 2022 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Haproxy Haproxy 2.2.0 (including) 2.2.21 (excluding)
Haproxy Haproxy 2.3.0 (including) 2.3.18 (excluding)
Haproxy Haproxy 2.4.0 (including) 2.4.13 (excluding)
Red Hat OpenShift Container Platform 4.6 RedHat haproxy-0:2.0.16-5.el8 *
Red Hat OpenShift Container Platform 4.7 RedHat haproxy-0:2.0.19-3.el8 *
Red Hat OpenShift Container Platform 4.8 RedHat haproxy-0:2.2.13-3.el8 *
Red Hat OpenShift Container Platform 4.9 RedHat haproxy-0:2.2.15-4.el8 *
Haproxy Ubuntu focal *
Haproxy Ubuntu impish *
Haproxy Ubuntu trusty *
Haproxy Ubuntu xenial *

References