Infinite loop in ConnMan - CVE-2022-23098
Published: September 19, 2022
Vulnerability identifier: #VU67467
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23098
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when handling TCP connections. A remote attacker can send specially crafted packets to the application, consume all available system resources and cause denial of service conditions.
Affected software
ConnMan
Debian Linux
Gentoo Linux
Ubuntu
connman (Ubuntu package)
connman (Debian package)
Debian Linux
Gentoo Linux
Ubuntu
connman (Ubuntu package)
connman (Debian package)
How to mitigate CVE-2022-23098
Install updates from vendor's website.
ConnMan - update to 1.41
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1
connman (Debian package) - update to 1.36-2.2+deb11u1
connman (Ubuntu package) - addressed in versions Ubuntu Pro, 1.36-2ubuntu0.1, 1.36-2.3ubuntu0.1, 1.41-2ubuntu0.23.04.1
connman (Debian package) - update to 1.36-2.2+deb11u1