CVE-2022-41723: Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
A flaw was found in golang. A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of requests.
Other sources
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
Golang Go is vulnerable to a denial of service, caused by a flaw in the HPACK decoder. By sending a specially-crafted HTTP/2 stream, a remote attacker could exploit this vulnerability to cause excessive CPU consumption, and results in a denial of service condition.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2023:4335
- RHSA-2023:3167
- RHSA-2023:4627
- RHSA-2023:3918
- RHSA-2023:5314
- RHBA-2023:3611
- RHSA-2023:3450
- RHSA-2023:4293
- RHSA-2023:1325
- RHSA-2023:1326
- RHSA-2023:3304
- RHSA-2023:3305
- RHSA-2023:3537
- RHSA-2023:3614
- RHSA-2023:4090
- RHSA-2023:4091
- RHSA-2023:4225
- RHSA-2023:4226
- RHSA-2023:4456
- RHSA-2023:4603
- RHSA-2023:4731
- RHSA-2023:4112
- RHSA-2023:4113
- RHSA-2023:3447
- RHSA-2023:3445
- RHSA-2023:3943
- RHSA-2023:4421
- RHSA-2023:4664
- RHSA-2023:5233
- RHSA-2023:3742
- RHSA-2023:3495
- RHSA-2023:3455
- RHSA-2023:4003
- IBM-7183851
Frequently Asked Questions
What is CVE-2022-41723?
CVE-2022-41723 is a vulnerability in golang that allows a maliciously crafted HTTP/2 stream to cause excessive CPU consumption and result in a denial of service.
What is the severity of CVE-2022-41723?
CVE-2022-41723 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2022-41723?
Openshift Serverless Clients version 1.8.1-3.el8, Openshift version 4.13.0-202304211155.p0.gb404935.assembly.stream.el9, Etcd version 3.3.23-14.el8, Skupper CLI version 1.4.1-2.el8 and 1.4.1-2.el9, Golang Go versions up to 1.19.6, Golang Go version 1.20.0, Golang Hpack version up to 0.7.0, Golang Http2 version up to 0.7.0, Golang.org/x/net version 0.7.0, Golang version 1.20.1, and Golang version 1.19.6 are affected by CVE-2022-41723.
How can CVE-2022-41723 be exploited?
CVE-2022-41723 can be exploited by sending a maliciously crafted HTTP/2 stream to the vulnerable software, causing excessive CPU consumption in the HPACK decoder.
Is there a fix available for CVE-2022-41723?
Yes, the fix for CVE-2022-41723 is available. Please refer to the official references for more information on how to apply the fix.