#VU70118 Infinite loop in Netty - CVE-2022-41881
Published: December 12, 2022 / Updated: July 18, 2024
Netty
Netty project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the HaProxyMessageDecoder when parsing a TLV with type of "PP2_TYPE_SSL". A remote attacker can pass a specially crafted message to consume all available system resources and cause denial of service conditions.