CVE-2022-41556: High severity Lighttpd Lighttpd vulnerability
A resource leak in gwbackend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of modfastcgi is, for example, affected. This is fixed in 1.4.67.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lighttpdto a version that resolves this vulnerability.Fixed in 1.4.53-4+deb10u2Fixed in 1.4.53-4+deb10u3Fixed in 1.4.59-1+deb11u2Fixed in 1.4.69-1 - Upgrade
Upgrade
lighttpdto a version that resolves this vulnerability.Fixed in 1.4.67
Event History
Frequently Asked Questions
What is CVE-2022-41556?
CVE-2022-41556 is a vulnerability in lighttpd versions 1.4.56 through 1.4.66 that could lead to a denial of service due to connection-slot exhaustion.
How does CVE-2022-41556 affect lighttpd?
CVE-2022-41556 affects lighttpd versions 1.4.56 through 1.4.66 by causing a resource leak in gw_backend.c, leading to connection-slot exhaustion and a denial of service.
What is the severity of CVE-2022-41556?
CVE-2022-41556 has a severity rating of 7.5 (high).
How can I fix CVE-2022-41556?
To fix CVE-2022-41556, it is recommended to update lighttpd to version 1.4.67 or apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2022-41556?
More information about CVE-2022-41556 can be found in the following references: [link1], [link2], [link3].