Bug 2134577 (CVE-2022-39271) - CVE-2022-39271 traefik: a closing HTTP/2 server connection could hang forever because of a subsequent fatal error
Summary: CVE-2022-39271 traefik: a closing HTTP/2 server connection could hang forever...
Keywords:
Status: NEW
Alias: CVE-2022-39271
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2134578
TreeView+ depends on / blocked
 
Reported: 2022-10-13 16:44 UTC by Marian Rehak
Modified: 2023-07-07 08:28 UTC (History)
1 user (show)

Fixed In Version: traefik 2.8.8, traefik 2.9.0-rc5
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2022-10-13 16:44:19 UTC
A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.

Reference:

https://github.com/traefik/traefik/security/advisories/GHSA-c6hx-pjc3-7fqr


Note You need to log in before you can comment on or make changes to this bug.