CVE-2022-41881: High severity ibm disconnected log collector vulnerability
A flaw was found in codec-haproxy from the Netty project. This flaw allows an attacker to build a malformed crafted message and cause infinite recursion, causing stack exhaustion and leading to a denial of service (DoS).
Other sources
Netty is vulnerable to a denial of service, caused by a StackOverflowError in HAProxyMessageDecoder. By sending a specially-crafted message, a remote attacker could exploit this vulnerability to cause an infinite recursion, and results in a denial of service condition.
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-41881?
CVE-2022-41881 is a vulnerability found in Netty project versions prior to 4.1.86.Final.
What is the severity of CVE-2022-41881?
CVE-2022-41881 has a severity level of high.
How does CVE-2022-41881 impact Netty project?
CVE-2022-41881 can lead to a StackOverflowError when parsing a malformed crafted message due to infinite recursion.
What is the remedy for CVE-2022-41881?
The remedy for CVE-2022-41881 is to update to Netty project version 4.1.86.Final.
Where can I find more information about CVE-2022-41881?
More information about CVE-2022-41881 can be found at the following references: [1] [2] [3].