CVE Vulnerabilities

CVE-2022-29190

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: May 21, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into an infinite loop when processing. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
DtlsPion*2.1.4 (excluding)
PionUbuntubionic*
SnowflakeUbuntuesm-apps/jammy*
SnowflakeUbuntujammy*
SnowflakeUbuntukinetic*
SnowflakeUbuntulunar*
SnowflakeUbuntumantic*
SnowflakeUbuntuoracular*
SnowflakeUbuntuupstream*
TelegrafUbuntuesm-apps/jammy*
TelegrafUbuntuimpish*
TelegrafUbuntujammy*
TelegrafUbuntukinetic*
TelegrafUbuntulunar*
TelegrafUbuntumantic*

References