CVE-2022-27781: High severity haxx curl vulnerability
A vulnerability was found in curl. This issue occurs due to an erroneous function. A malicious server could make curl within Network Security Services (NSS) get stuck in a never-ending busy loop when trying to retrieve that information. This flaw allows an Infinite Loop, affecting system availability.
Other sources
libcurl provides the CURLOPTCERTINFO option to allow applications to request details to be returned about a TLS server's certificate chain. Due to an erroneous function, a malicious server could make libcurl built with NSS get stuck in a never-ending busy-loop when trying to retrieve that information
— Red Hat
libcurl provides the CURLOPTCERTINFO option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
— Microsoft
libcurl provides the CURLOPTCERTINFO option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-27781.
What software is affected by this vulnerability?
The affected software includes curl, jbcs-httpd24-curl, Debian Linux, Haxx Curl, NetApp Clustered Data ONTAP, NetApp Solidfire, Enterprise SDS & HCI Storage Node, and NetApp Solidfire & HCI Management Node.
What is the severity of CVE-2022-27781?
The severity of CVE-2022-27781 is high with a severity value of 7.5.
How can I fix this vulnerability in Red Hat systems?
To fix this vulnerability in Red Hat systems, update the curl package to version 7.83.1 or higher.
Where can I find more information about CVE-2022-27781?
You can find more information about CVE-2022-27781 on the Red Hat Bugzilla and Red Hat Advisory pages.