CVE Vulnerabilities

CVE-2022-0711

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
HaproxyHaproxy2.2.0 (including)2.2.21 (excluding)
HaproxyHaproxy2.3.0 (including)2.3.18 (excluding)
HaproxyHaproxy2.4.0 (including)2.4.13 (excluding)
Red Hat OpenShift Container Platform 4.6RedHathaproxy-0:2.0.16-3.el7*
Red Hat OpenShift Container Platform 4.7RedHathaproxy-0:2.0.19-3.el7*
Red Hat OpenShift Container Platform 4.8RedHathaproxy-0:2.2.13-3.el8*
Red Hat OpenShift Container Platform 4.9RedHathaproxy-0:2.2.15-4.el8*
HaproxyUbuntuesm-infra/focal*
HaproxyUbuntufocal*
HaproxyUbuntuimpish*
HaproxyUbuntutrusty*
HaproxyUbuntuxenial*

References