Reachable Assertion in Varnish Cache - CVE-2022-38150
Published: August 9, 2022 / Updated: November 28, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when processing HTTP/1 responses from configured backends. A remote attacker with ability to influence server response can pass specially crafted reason phrase of the backend response status line and perform a denial of service (DoS) attack.
Affected software
openEuler
Fedora
varnish-modules
varnish
varnish-debuginfo
varnish-devel
varnish-debugsource
varnish-help
How to mitigate CVE-2022-38150
varnish-modules - update to 0.19.0-5.fc36
varnish - addressed in versions 6.6.2-3.fc35, 7.0.3-1.fc36
varnish - update to 7.0.1-6
varnish-debuginfo - update to 7.0.1-6
varnish-devel - update to 7.0.1-6
varnish-debugsource - update to 7.0.1-6
varnish-help - update to 7.0.1-6