First published: Tue May 10 2022(Updated: )
.NET and Visual Studio Denial of Service Vulnerability
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET | =5.0 | |
Microsoft .NET | =6.0.0 | |
Microsoft .NET Core | =3.1 | |
Microsoft Visual Studio 2019 | >=16.0<=16.0.11 | |
Microsoft Visual Studio 2022 | =17.0 | |
Microsoft Visual Studio 2022 | =17.1 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
nuget/Microsoft.AspNetCore.App.Runtime.osx-arm64 | >=6.0.0<6.0.5 | 6.0.5 |
nuget/Microsoft.Owin | <4.2.2 | 4.2.2 |
nuget/Microsoft.Owin.Security.Cookies | <4.2.2 | 4.2.2 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=3.0.0<=3.1.24 | 3.1.25 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=6.0.0<=6.0.4 | 6.0.5 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=5.0.0<=5.0.16 | 5.0.17 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=3.0.0<=3.1.24 | 3.1.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29117 is a denial of service vulnerability in .NET and Visual Studio.
CVE-2022-29117 has a severity rating of 7.5 (high).
Microsoft .NET 5.0, Microsoft .NET 6.0.0, Microsoft .NET Core 3.1, Microsoft Visual Studio 2019 (16.0.0 - 16.0.11), and Microsoft Visual Studio 2022 (17.0, 17.1) are affected by CVE-2022-29117.
Apply the security patches provided by Microsoft and update to the latest versions of the affected software.
You can find more information about CVE-2022-29117 at the following references: [reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNXQL7EZORGU4PZCPJ5EPQ4P7IEY3ZZO/), [reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IBYSBUDJYQ76HK4TULXVIIPCKK2U6WDB/), [reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W5FPEQ6BTYRGTS6IYCDTZW6YF5HLQ3BY/).