CVE-2022-32206: Input Validation
A vulnerability was found in curl. This issue occurs because the number of acceptable "links" in the "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.
Other sources
Accelerate Framework. A memory consumption issue was addressed with improved memory handling.
— Apple
APFS. An access issue was addressed with improved access restrictions.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleAVD. A memory corruption issue was addressed with improved state management.
— Apple
AppleAVD. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.86.0-2.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.86.0-2.el7 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 0:7.61.1-22.el8_6.4 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 0:7.61.1-18.el8_4.3 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 0:7.76.1-14.el9_0.5 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.64.0-4+deb10u7Fixed in 7.74.0-1.3+deb11u9Fixed in 7.74.0-1.3+deb11u10Fixed in 7.88.1-10+deb12u3Fixed in 7.88.1-10+deb12u4Fixed in 8.4.0-2 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 7.84.0 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 7.84.0Patch Multiple issues were addressed by updating to curl version 7.84.0. - Configuration
Prevent use of chained HTTP compression algorithms (multiple/composed compression steps), since curl versions earlier than 7.84.0 support them and the unbounded decompression chain can cause a malloc bomb/DoS.
curl chained HTTP compression algorithms = disabled - Configuration
Remove the additional entitlements related to this issue on third-party apps, as described: “This issue was addressed by removing additional entitlements.”
third-party apps sandbox sandbox entitlements / entitlements removed = removed (vulnerable entitlements) - Configuration
Use the improved code signature validation logic/checks mentioned in the text: “An issue in code signature validation was addressed with improved checks.”
code signing validation certificate/code signature validation checks = improved - Compensating control
Apply the “additional sandbox restrictions” for third-party apps to address the described access issues: “An access issue was addressed with additional sandbox restrictions on third-party apps,” and “An access issue was addressed with additional sandbox restrictions,” and “An access issue was addressed with improved access restrictions.”
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42795
- CVE-2022-48577
- CVE-2022-32858
- CVE-2022-32898
- CVE-2022-32899
- CVE-2022-46721
- CVE-2022-47915
- CVE-2022-47965
- CVE-2022-32889
- CVE-2022-32907
- CVE-2022-32827
- CVE-2022-32877
- CVE-2022-42789
- CVE-2022-42825
- CVE-2022-46722
- CVE-2022-32902
- CVE-2022-32904
- CVE-2022-32890
- CVE-2022-42796
- CVE-2022-42798
- CVE-2022-32940
- CVE-2022-42816
- CVE-2022-42821
- CVE-2022-42860
- CVE-2022-42819
- CVE-2022-42813
- CVE-2022-26730
- CVE-2022-32945
- CVE-2022-42838
- CVE-2022-48683
- CVE-2022-22663
- CVE-2022-32867
- CVE-2022-32205
- CVE-2022-32206
- CVE-2022-32207
- CVE-2022-32208
- CVE-2022-42814
- CVE-2022-32865
- CVE-2022-32915
- CVE-2022-32928
- CVE-2022-22643
- CVE-2022-32935
- CVE-2022-42788
- CVE-2022-48504
- CVE-2022-32905
- CVE-2022-42833
- CVE-2022-32947
- CVE-2022-42809
- CVE-2022-3437
- CVE-2022-32849
- CVE-2022-32913
- CVE-2022-32809
- CVE-2022-1622
- CVE-2022-32936
- CVE-2022-42820
- CVE-2022-42806
- CVE-2022-32864
- CVE-2022-32866
- CVE-2022-32911
- CVE-2022-32924
- CVE-2022-32914
- CVE-2022-42808
- CVE-2022-32944
- CVE-2022-42803
- CVE-2022-32926
- CVE-2022-42801
- CVE-2022-46712
- CVE-2022-42815
- CVE-2022-42834
- CVE-2022-46707
- CVE-2022-32883
- CVE-2022-32908
- CVE-2022-42810
- CVE-2021-39537
- CVE-2022-29458
- CVE-2022-42818
- CVE-2022-32879
- CVE-2022-32895
- CVE-2022-46713
- CVE-2022-42807
- CVE-2022-32918
- CVE-2022-42829
- CVE-2022-42830
- CVE-2022-42831
- CVE-2022-42832
- CVE-2022-32941
- CVE-2022-28739
- CVE-2022-32881
- CVE-2022-32862
- CVE-2022-32931
- CVE-2022-42811
- CVE-2022-42793
- CVE-2022-32876
- CVE-2022-32938
- CVE-2022-42790
- CVE-2022-32870
- CVE-2022-32934
- CVE-2022-42791
- CVE-2021-36690
- CVE-2022-48505
- CVE-2022-26699
- CVE-2022-0261
- CVE-2022-0318
- CVE-2022-0319
- CVE-2022-0351
- CVE-2022-0359
- CVE-2022-0361
- CVE-2022-0368
- CVE-2022-0392
- CVE-2022-0554
- CVE-2022-0572
- CVE-2022-0629
- CVE-2022-0685
- CVE-2022-0696
- CVE-2022-0714
- CVE-2022-0729
- CVE-2022-0943
- CVE-2022-1381
- CVE-2022-1420
- CVE-2022-1725
- CVE-2022-1616
- CVE-2022-1619
- CVE-2022-1620
- CVE-2022-1621
- CVE-2022-1629
- CVE-2022-1674
- CVE-2022-1733
- CVE-2022-1735
- CVE-2022-1769
- CVE-2022-1927
- CVE-2022-1942
- CVE-2022-1968
- CVE-2022-1851
- CVE-2022-1897
- CVE-2022-1898
- CVE-2022-1720
- CVE-2022-2000
- CVE-2022-2042
- CVE-2022-2124
- CVE-2022-2125
- CVE-2022-2126
- CVE-2022-42828
- CVE-2022-32875
- CVE-2022-42826
- CVE-2022-32886
- CVE-2022-32888
- CVE-2022-32912
- CVE-2022-42799
- CVE-2022-42823
- CVE-2022-42824
- CVE-2022-32923
- CVE-2022-32922
- CVE-2022-32892
- CVE-2022-32833
- CVE-2022-46709
- CVE-2022-37434
- CVE-2022-42800
Frequently Asked Questions
What is CVE-2022-32206?
CVE-2022-32206 is a vulnerability in curl that allows a malicious server to insert a virtually unlimited number of links in the decompression chain.
How severe is CVE-2022-32206?
CVE-2022-32206 has a severity rating of 6.5 (Medium).
What software is affected by CVE-2022-32206?
Software versions of curl < 7.84.0 and some versions of jbcs-httpd24-curl, curl for Red Hat, curl for Debian, and Apple macOS Ventura are affected by CVE-2022-32206.
How can I fix CVE-2022-32206?
To fix CVE-2022-32206, update your curl software to version 7.84.0 or higher.
Where can I find more information about CVE-2022-32206?
You can find more information about CVE-2022-32206 at the following sources: CVE website, NIST NVD, curl documentation, Red Hat Bugzilla, and Red Hat Security Advisory.