Vulnerability Name: | CVE-2022-23471 (CCN-241615) | ||||||||||||||||
Assigned: | 2022-12-07 | ||||||||||||||||
Published: | 2022-12-07 | ||||||||||||||||
Updated: | 2023-07-11 | ||||||||||||||||
Summary: | containerd is vulnerable to a denial of service, caused by a flaw in the CRI implementation. By sending a specially-crafted request, a remote authenticated attacker could exploit this vulnerability to exhaust memory on the host, and results in a denial of service condition. | ||||||||||||||||
CVSS v3 Severity: | 5.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H) 5.0 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C)
| ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-23471 Source: XF Type: UNKNOWN containerd-cve202223471-dos(241615) Source: security-advisories@github.com Type: Patch, Third Party Advisory security-advisories@github.com Source: CCN Type: containerd GIT Repository containerd CRI stream server: Host memory exhaustion through Terminal resize goroutine leak Source: security-advisories@github.com Type: Third Party Advisory security-advisories@github.com | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |