Resource exhaustion in Helm - CVE-2022-36055

 

Resource exhaustion in Helm - CVE-2022-36055

Published: October 5, 2022


Vulnerability identifier: #VU67945
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36055
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect resource management within the strvals package, responsible for converting strings into Go structures. A remote attacker can pass specially crafted input to the application and consume all available memory on the system.


Affected software

Helm
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Communications Unified Assurance
SUSE Linux Enterprise Module for Packagehub Subpackages
helm3
helm
helm-debuginfo
helm-bash-completion
helm-fish-completion
helm-zsh-completion
IBM Cloud Transformation Advisor
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
IBM DB2

How to mitigate CVE-2022-36055

Install updates from vendor's website.

Helm - update to 3.9.4
helm3 - update to 3.3.3-150100.1.7.1
IBM Cloud Transformation Advisor - update to 3.5.0
IBM Cloud Pak for Watson AIOps - update to 3.6.1
helm - update to 3.9.4-150000.1.10.3
helm-debuginfo - update to 3.9.4-150000.1.10.3
helm-bash-completion - update to 3.9.4-150000.1.10.3
helm-fish-completion - update to 3.9.4-150000.1.10.3
helm-zsh-completion - update to 3.9.4-150000.1.10.3
IBM DB2 - update to 4.6
DB2 Warehouse on Cloud Pak for Data - update to 4.6

External References

Related Security Bulletins