First published: Mon Jun 20 2022(Updated: )
A vulnerability was found in curl. This issue occurs because the number of acceptable "links" in the "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.
Credit: CVE-2022-32205 CVE-2022-32206 CVE-2022-32207 CVE-2022-32208 support@hackerone.com Arsenii Kostromin (0x3c3e) Kshitij Kumar CrowdstrikeJai Musunuri CrowdstrikeSergii Kryvoblotskyi MacPaw IncLinus Henze Pinauten GmbHTommy Muir @Muirey03 Jiří Vinopal @vinopaljiri Check Point ResearchSonali Luthar the University of VirginiaMichael Liao the University of Illinois at UrbanaRohan Pahwa Rutgers University University of FloridaBao Nguyen University of FloridaBistrit Dahal Csaba Fitzl @theevilbit Offensive SecurityWojciech Reguła SecuRingRon Masas (breakpoint.sh) BreakPoint Technologies LTDPan ZhenPeng @Peterpan0927 Asahi Lina @LinaAsahi Yutao Wang @Jack Yu Zhou @yuzhou6666 Evgeny Legerov IntevydisJoshua Jones Yiğit Can YILMAZ @yilmazcanyigit Mickey Jin @patch1t CVE-2022-1622 Antonio Zekic @antoniozekic Peter Pan ZhenPeng STAR LabsTingting Yin Tsinghua UniversityZweig Kunlun LabIan Beer Google Project ZeroTim Michaud @TimGMichaud MoveworksXinru Chi Pangu LabJohn Aakerblom @jaakerblom Wojciech Reguła @_r3ggi SecuRingRon Masas breakpointhqan anonymous researcher Xingwei Lin @xwlin_roy Ant Security LightYinyi Wu Ant Security LightCVE-2021-39537 CVE-2022-29458 Gustav Hansen WithSecureUbeydullah Sümer Mickey Jin @patch1t Trend MicroEzekiel Elin Ashwani Rajput Nagarro Software PvtSrijan Shivam Mishra The Hack ReportJugal Goradia Aastha TechnologiesEvan Ricafort (evanricafort.com) Invalid Web SecurityShesha Sai C (linkedin.com/in/shesha-sai-c-18585b125) Pune PuneAmod Raghunath Patwardhan PuneIndia CVE-2022-28739 Rohit Chatterjee University of Illinois UrbanaJustin Bui @slyd0g SnowflakeCristian Dinca Tudor Vianu National High School of Computer Science ofOm kothawade Zaprico DigitalAndrew Goldberg The McCombs School of BusinessThe University Texas at AustinFelix Poulin-Belanger CVE-2021-36690 Adam Chester TrustedSecThijs Alkemade @xnyhps Computest Sectorrancisco Alonso @revskills P1umer @p1umer afang @afang5472 xmzyshypnc @xmzyshypnc1 Jeonghoon Shin at Theori @singi21a Trend Micro Zero Day InitiativeJihwan Kim @gPayl0ad Dohyun Lee @l33d0hyun Dohyun Lee @l33d0hyun SSD LabsAbdulrahman Alqabandi Microsoft Browser Vulnerability ResearchRyan Shin IAAI SecLab at Korea UniversityDohyun Lee @l33d0hyun DNSLab at Korea UniversityWonyoung Jung @nonetype_pwn KAIST Hacking LabYonghwi Jin at Theori @jinmo123 Trend Micro Zero Day Initiative楼梦想改造家 @18 DBAppSecurity's WeBin lab @jq0904 DBAppSecurity's WeBin labJeff Johnson Wang Yu CyberservalEvgeny Legerov Yinyi Wu Google Project ZeroABC Research s.r.o Google Project ZeroNatalie Silvanovich Google Project ZeroTommaso Bianco @cutesmilee__ Antonio Zekic @antoniozekic Google Project ZeroKoh M. Nakagawa FFRI Security IncAnonymous Trend Micro Zero Day InitiativeABC Research s.r.o. Jonathan Bar Or MicrosoftJonathan Zhang Open Computing FacilityDavid Hoyt Hoyt LLCGuilherme Rambo Best Buddy AppsHalle Winkler @hallewinkler PolitepixThijs Alkemade Computest Sector 7Arsenii Kostromin Mohamed Ghannam @_simo36 ryuzaki
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-curl | <0:7.86.0-2.el8 | 0:7.86.0-2.el8 |
redhat/jbcs-httpd24-curl | <0:7.86.0-2.el7 | 0:7.86.0-2.el7 |
redhat/curl | <0:7.61.1-22.el8_6.4 | 0:7.61.1-22.el8_6.4 |
redhat/curl | <0:7.61.1-18.el8_4.3 | 0:7.61.1-18.el8_4.3 |
redhat/curl | <0:7.76.1-14.el9_0.5 | 0:7.76.1-14.el9_0.5 |
debian/curl | <=7.64.0-4+deb10u2 | 7.64.0-4+deb10u7 7.74.0-1.3+deb11u9 7.74.0-1.3+deb11u10 7.88.1-10+deb12u3 7.88.1-10+deb12u4 8.4.0-2 |
redhat/curl | <7.84.0 | 7.84.0 |
Apple macOS | <13 | 13 |
haxx curl | <7.84.0 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
NetApp Clustered Data ONTAP | ||
NetApp Element Software | ||
netapp hci management node | ||
netapp solidfire | ||
netapp bootstrap os | ||
netapp hci compute node | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h410s firmware | ||
netapp h410s | ||
Siemens Scalance SC622-2C Firmware | <3.0 | |
Siemens Scalance SC622-2C | ||
Siemens Scalance SC626-2C | <3.0 | |
Siemens Scalance SC626-2C Firmware | ||
Siemens Scalance SC632-2C Firmware | <3.0 | |
Siemens Scalance SC632-2C | ||
Siemens Scalance SC636-2C | <3.0 | |
Siemens Scalance SC636-2C | ||
Siemens Scalance SC642-2C | <3.0 | |
Siemens Scalance SC642-2C Firmware | ||
Siemens Scalance SC646-2C Firmware | <3.0 | |
siemens scalance sc646-2c firmware | ||
All of | ||
netapp hci compute node | ||
netapp bootstrap os | ||
All of | ||
netapp h300s | ||
netapp h300s firmware | ||
All of | ||
netapp h500s | ||
NetApp H500S Firmware | ||
All of | ||
netapp h700s | ||
netapp h700s firmware | ||
All of | ||
netapp h410s | ||
netapp h410s firmware | ||
All of | ||
Siemens Scalance SC622-2C | ||
Siemens Scalance SC622-2C Firmware | <3.0 | |
All of | ||
Siemens Scalance SC626-2C Firmware | ||
Siemens Scalance SC626-2C | <3.0 | |
All of | ||
Siemens Scalance SC632-2C Firmware | <3.0 | |
Siemens Scalance SC632-2C | ||
All of | ||
Siemens Scalance SC636-2C | <3.0 | |
Siemens Scalance SC636-2C | ||
All of | ||
Siemens Scalance SC642-2C | <3.0 | |
Siemens Scalance SC642-2C Firmware | ||
All of | ||
Siemens Scalance SC646-2C Firmware | <3.0 | |
siemens scalance sc646-2c firmware | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2022-32206 is a vulnerability in curl that allows a malicious server to insert a virtually unlimited number of links in the decompression chain.
CVE-2022-32206 has a severity rating of 6.5 (Medium).
Software versions of curl < 7.84.0 and some versions of jbcs-httpd24-curl, curl for Red Hat, curl for Debian, and Apple macOS Ventura are affected by CVE-2022-32206.
To fix CVE-2022-32206, update your curl software to version 7.84.0 or higher.
You can find more information about CVE-2022-32206 at the following sources: CVE website, NIST NVD, curl documentation, Red Hat Bugzilla, and Red Hat Security Advisory.