Bug 1208551 (CVE-2022-31394) - VUL-0: TRACKERBUG: CVE-2022-31394: hyper: max header list size not settable allowing deny of service
Summary: VUL-0: TRACKERBUG: CVE-2022-31394: hyper: max header list size not settable a...
Status: NEW
Alias: CVE-2022-31394
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/357841/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-31394:5.3:(AV:...
Keywords:
Depends on: 1208557 1208558 1208560 1208561 1208562 1208552 1208553 1208554 1208555 1208556 1208559
Blocks:
  Show dependency treegraph
 
Reported: 2023-02-22 07:47 UTC by Thomas Leroy
Modified: 2024-05-06 08:17 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Thomas Leroy 2023-02-22 07:50:24 UTC
Packages embedding a vulnerable version of the hyper crate:

SUSE:SLE-15-SP3:Update/rustup,2,hyper,0.14.5
SUSE:SLE-15-SP3:Update/rustup,2,hyper,0.14.13
SUSE:SLE-15-SP3:Update/sccache,1,hyper,0.12.35
SUSE:SLE-15-SP3:Update/sccache,1,hyper,0.12.36
SUSE:SLE-15-SP3:Update:Products:MicroOS52:Update/afterburn,1,hyper,0.14.11
SUSE:SLE-15-SP4:Update/aws-nitro-enclaves-cli,2,hyper,0.14.16
SUSE:SLE-15-SP4:Update/gstreamer-plugins-rs,1,hyper,0.14.17
SUSE:SLE-15-SP4:Update/rustup,1,hyper,0.14.13
SUSE:SLE-15-SP4:Update/rustup,1,hyper,0.14.5
SUSE:SLE-15-SP4:Update/sccache,1,hyper,0.12.35
SUSE:SLE-15-SP4:Update/sccache,1,hyper,0.12.36
SUSE:SLE-15-SP4:Update:Products:Micro53:Update/afterburn,1,hyper,0.14.11
openSUSE:Factory/afterburn,9,hyper,0.14.17
openSUSE:Factory/aws-nitro-enclaves-cli,4,hyper,0.14.16
openSUSE:Factory/fractal,13,hyper,0.14.5
openSUSE:Factory/gnome-podcasts,2,hyper,0.14.16
openSUSE:Factory/pijul,10,hyper,0.14.18
openSUSE:Factory/sccache,21,hyper,0.14.5
openSUSE:Factory/spotifyd,13,hyper,0.13.10
openSUSE:Factory/spotifyd,13,hyper,0.13.2
openSUSE:Factory/spotifyd,13,hyper,0.14.5
openSUSE:Factory/tectonic,1,hyper,0.12.36
openSUSE:Factory/tectonic,1,hyper,0.14.18
openSUSE:Factory/wasm-pack,3,hyper,0.12.36