Resource exhaustion in yaml - CVE-2022-3064
Published: February 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing large YAML documents. A remote attacker can consume excessive amounts of CPU or memory and perform a denial of service (DoS) attack.
Affected software
API Portal
Red Hat OpenShift GitOps
Red Hat OpenShift Container Platform
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Ubuntu
openEuler
Event Streams
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
golang-gopkg-yaml.v2-dev (Ubuntu package)
golang-yaml.v2-dev (Ubuntu package)
toolbox-tests
toolbox
toolbox (Red Hat package)
rhc (Red Hat package)
udica
gmailctl
caddy
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
crun
fuse-overlayfs
skopeo-tests
skopeo
buildah-tests
buildah
containers-common
manifest-tool
conmon
container-selinux
exercism
etcd (Red Hat package)
etcd
python3-criu
criu-libs
criu-devel
criu
crit
libslirp
libslirp-devel
python3-podman
podman-docker
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
moby-engine
cockpit-podman
Planning Analytics Connector for SAP
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2022-3064
API Portal - update to May 2023
Red Hat OpenShift Container Platform - addressed in versions 4.9.56, 4.10.52, 4.10.53, 4.10.60, 4.11.40, 4.12.16, 4.13.33
Event Streams - update to 11.1.4
golang-gopkg-yaml.v2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.2-1ubuntu0.1
golang-yaml.v2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.2-1ubuntu0.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
toolbox (Red Hat package) - update to 0.0.99.4-6.el9_3
rhc (Red Hat package) - addressed in versions 0.2.5-1.el8_10, 0.2.5-1.el9_5
udica - update to 0.2.6-20
gmailctl - addressed in versions 0.10.6-2.fc36, 0.10.6-2.fc37, 0.10.6-3.fc38
Planning Analytics Connector for SAP - update to 1.0 IF1
caddy - update to 1.0.5-1.el7
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo-tests - update to 1.13.3-3.0.1
skopeo - update to 1.13.3-3.0.1
buildah-tests - update to 1.31.3-1
buildah - update to 1.31.3-1
containers-common - update to 1-71.0.1
manifest-tool - addressed in versions 2.0.8-1.fc36, 2.0.8-1.fc37, 2.0.8-1.fc38
conmon - update to 2.1.8-1
IBM Fusion HCI - update to 2.6.1
container-selinux - update to 2.221.0-1
exercism - addressed in versions 3.2.0-1.fc37, 3.2.0-1.fc38, 3.2.0-1.fc39
etcd (Red Hat package) - addressed in versions 3.3.23-12.el8ost, 3.4.14-3.el9ost
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
Red Hat OpenShift Dev Spaces - update to 3.15.0
python3-criu - update to 3.18-5
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
IBM Cloud Pak for Watson AIOps - update to 4.1
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman-docker - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
cockpit-podman - update to 75-1
External References
Related Security Bulletins
- Denial of service in YAML
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Red Hat OpenStack Platform 17 update for etcd
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Resource exhaustion in IBM Event Streams
- Red Hat OpenStack Platform update for etcd
- OpenShift Container Platform 4.12 update for go-yaml
- OpenShift Container Platform 4.11 update for go-yaml
- OpenShift Container Platform 4.10 update for yaml
- Multiple vulnerabilities in Axway API Portal
- Ubuntu update for golang-yaml.v2
- Fedora 38 update for manifest-tool
- Fedora 36 update for manifest-tool
- Fedora 37 update for manifest-tool
- Fedora 36 update for gmailctl
- Fedora 37 update for gmailctl
- Fedora 38 update for gmailctl
- Fedora EPEL 7 update for caddy
- Fedora 38 update for exercism
- Fedora 37 update for exercism
- Fedora 39 update for exercism
- Fedora 39 update for moby-engine
- Fedora 37 update for moby-engine
- Fedora 38 update for moby-engine
- Multiple vulnerabilities in IBM Storage Fusion and IBM Storage Fusion HCI
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Red Hat Enterprise Linux 9 update for toolbox
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Planning Analytics Connector for SAP
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Red Hat Enterprise Linux 9 update for rhc
- Red Hat Enterprise Linux 8 update for rhc
- openEuler 20.03 LTS SP4 update for etcd
- openEuler 22.03 LTS SP3 update for etcd
- openEuler 22.03 LTS SP4 update for etcd
- Anolis OS update for container-tools:an8 module