Infinite loop in ConnMan - CVE-2022-23098

 

Infinite loop in ConnMan - CVE-2022-23098

Published: September 19, 2022


Vulnerability identifier: #VU67467
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23098
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when handling TCP connections. A remote attacker can send specially crafted packets to the application, consume all available system resources and cause denial of service conditions.


Affected software

ConnMan
Debian Linux
Gentoo Linux
Ubuntu
connman (Ubuntu package)
connman (Debian package)

How to mitigate CVE-2022-23098

Install updates from vendor's website.

ConnMan - update to 1.41
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1
connman (Debian package) - update to 1.36-2.2+deb11u1

External References

Related Security Bulletins