Resource exhaustion in containerd - CVE-2022-23471

 

Resource exhaustion in containerd - CVE-2022-23471

Published: December 8, 2022


Vulnerability identifier: #VU70039
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23471
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in containerd CRI stream server when handling terminal resize events. A remote user can request a TTY and force it to fail by sending a faulty command and exhaust memory on the host.


Affected software

containerd
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
DB2 Data Management Console
DB2 Data Management Console on CPD
Dell EMC Streaming Data Platform
IBM Cloud Pak for Watson AIOps
IBM Watson Machine Learning Accelerator
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
IBM Concert Software
IBM MQ Operator
IBM Match 360
Data Replication on Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
IBM Decision Optimization for Cloud Pak for Data
QRadar Suite
IBM Edge Application Manager
SUSE Linux Enterprise Module for Packagehub Subpackages
golang-github-containerd-cgroups
containerd
containerd (Ubuntu package)
containerd-ctr
app-containers/containerd
containerd-devel
moby-engine
Cloud Pak for Data
Dell EMC VxRail Appliance
IBM InfoSphere Information Server

How to mitigate CVE-2022-23471

Install updates from vendor's website.

containerd - addressed in versions 1.5.16, 1.6.12
QRadar Suite - update to 1.10.19.0
IBM Cloud Transformation Advisor - update to 3.10.2
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
IBM Concert Software - update to 1.0.1
golang-github-containerd-cgroups - update to 1.0.4-3.fc37
containerd - update to 1.2.0-207
containerd (Ubuntu package) - addressed in versions 1.5.9-0ubuntu1~18.04.2, 1.5.9-0ubuntu1~20.04.6, 1.5.9-0ubuntu3.1, 1.6.4-0ubuntu1.1
containerd - addressed in versions 1.6.12-150000.79.1, 1.6.16-16.71.1, 1.6.16-150000.82.2
containerd-ctr - addressed in versions 1.6.12-150000.79.1, 1.6.16-150000.82.2
app-containers/containerd - update to 1.6.14
containerd - addressed in versions 1.6.14-2.fc37, 1.6.23-1.fc37, 1.6.23-1.fc38
containerd-devel - update to 1.6.16-150000.82.2
containerd - update to 1.6.19-1
Dell EMC Streaming Data Platform - update to 1.7.0
IBM MQ Operator - addressed in versions 2.0.17, 3.0.0
IBM Cloud Pak for Watson AIOps - update to 4.1.2
IBM Watson Machine Learning Accelerator - addressed in versions 4.2.0, 4.8.0
IBM Match 360 - update to 4.7.0
Data Replication on Cloud Pak for Data - update to 4.8.0
IBM Cloud Pak for Data Scheduling - update to 4.8.0
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Dell EMC VxRail Appliance - update to 7.0.411
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
moby-engine - update to 20.10.21-1.fc37
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.6, 23.0.6

External References

Related Security Bulletins