Описание
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
A flaw was found in HAProxy. An attacker can trigger HPACK dynamic table insertions under memory pressure, leading to a null pointer dereference in the hpack_dht_insert() function. This can cause HAProxy worker processes to crash, resulting in a denial of service (DoS).
Отчет
This Important flaw in HAProxy can lead to a denial of service. An unauthenticated remote attacker could exploit a null pointer dereference by triggering HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash. This impacts the availability of services relying on HAProxy as a load balancer or proxy.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 5 | rhceph/rhceph-haproxy-rhel8 | Affected | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Ceph Storage 7 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Ceph Storage 8 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Ceph Storage 9 | rhceph-ci/haproxy | Affected | ||
| Red Hat Ceph Storage 9 | rhceph/rhceph-haproxy-rhel10 | Affected | ||
| Red Hat Ceph Storage 9 | rhceph/rhceph-haproxy-rhel9 | Affected | ||
| Red Hat Enterprise Linux 10 | haproxy | Affected | ||
| Red Hat Enterprise Linux 7 | haproxy | Out of support scope | ||
| Red Hat Enterprise Linux 8 | haproxy | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null point ...
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
7.5 High
CVSS3