Resource exhaustion in yaml - CVE-2022-3064

 

Resource exhaustion in yaml - CVE-2022-3064

Published: February 16, 2023


Vulnerability identifier: #VU72314
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3064
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing large YAML documents. A remote attacker can consume excessive amounts of CPU or memory and perform a denial of service (DoS) attack.


Affected software

yaml
API Portal
Red Hat OpenShift GitOps
Red Hat OpenShift Container Platform
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Ubuntu
openEuler
Event Streams
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
golang-gopkg-yaml.v2-dev (Ubuntu package)
golang-yaml.v2-dev (Ubuntu package)
toolbox-tests
toolbox
toolbox (Red Hat package)
rhc (Red Hat package)
udica
gmailctl
caddy
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
crun
fuse-overlayfs
skopeo-tests
skopeo
buildah-tests
buildah
containers-common
manifest-tool
conmon
container-selinux
exercism
etcd (Red Hat package)
etcd
python3-criu
criu-libs
criu-devel
criu
crit
libslirp
libslirp-devel
python3-podman
podman-docker
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
moby-engine
cockpit-podman
Planning Analytics Connector for SAP
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2022-3064

Install updates from vendor's website.

yaml - update to 2.2.4
API Portal - update to May 2023
Red Hat OpenShift Container Platform - addressed in versions 4.9.56, 4.10.52, 4.10.53, 4.10.60, 4.11.40, 4.12.16, 4.13.33
Event Streams - update to 11.1.4
golang-gopkg-yaml.v2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.2-1ubuntu0.1
golang-yaml.v2-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.2.2-1ubuntu0.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
toolbox (Red Hat package) - update to 0.0.99.4-6.el9_3
rhc (Red Hat package) - addressed in versions 0.2.5-1.el8_10, 0.2.5-1.el9_5
udica - update to 0.2.6-20
gmailctl - addressed in versions 0.10.6-2.fc36, 0.10.6-2.fc37, 0.10.6-3.fc38
Planning Analytics Connector for SAP - update to 1.0 IF1
caddy - update to 1.0.5-1.el7
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo-tests - update to 1.13.3-3.0.1
skopeo - update to 1.13.3-3.0.1
buildah-tests - update to 1.31.3-1
buildah - update to 1.31.3-1
containers-common - update to 1-71.0.1
manifest-tool - addressed in versions 2.0.8-1.fc36, 2.0.8-1.fc37, 2.0.8-1.fc38
conmon - update to 2.1.8-1
IBM Fusion HCI - update to 2.6.1
container-selinux - update to 2.221.0-1
exercism - addressed in versions 3.2.0-1.fc37, 3.2.0-1.fc38, 3.2.0-1.fc39
etcd (Red Hat package) - addressed in versions 3.3.23-12.el8ost, 3.4.14-3.el9ost
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
Red Hat OpenShift Dev Spaces - update to 3.15.0
python3-criu - update to 3.18-5
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
IBM Cloud Pak for Watson AIOps - update to 4.1
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman-docker - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
cockpit-podman - update to 75-1

External References

Related Security Bulletins