CVE-2022-21716
Summary
| CVE | CVE-2022-21716 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-03 21:15:00 UTC |
| Updated | 2023-11-07 03:43:00 UTC |
| Description | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: python-twisted-22.4.0-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Release Twisted 22.2.0 · twisted/twisted · GitHub |
MISC |
github.com |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Twisted SSH client and server denial of service during SSH handshake. · Advisory · twisted/twisted · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 35 Update: python-twisted-22.4.0-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Twisted: Multiple Vulnerabilities (GLSA 202301-02) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 36 Update: python-twisted-22.4.0-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| #10284 (Denial of service in SSH transport for twisted)
– Twisted |
MISC |
twistedmatrix.com |
|
| [SECURITY] [DLA 2938-1] twisted security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 36 Update: python-twisted-22.4.0-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Update the release date. · twisted/twisted@89c395e · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179114 Debian Security Update for twisted (DLA 2938-1)
- 180874 Debian Security Update for twisted (CVE-2022-21716)
- 198719 Ubuntu Security Notification for Twisted Vulnerabilities (USN-5354-1)
- 198774 Ubuntu Security Notification for Twisted Vulnerability (USN-5354-2)
- 240180 Red Hat Update for OpenStack Platform 16.1 (RHSA-2022:0982)
- 240181 Red Hat Update for OpenStack Platform 16.2 (RHSA-2022:0992)
- 282889 Fedora Security Update for python (FEDORA-2022-9a489fa494)
- 282890 Fedora Security Update for python (FEDORA-2022-71b66d4747)
- 296057 Oracle Solaris 11.4 Support Repository Update (SRU) 44.113.4 Missing (bulletinapr2022)
- 353965 Amazon Linux Security Advisory for python-twisted-conch : ALAS-2022-1592
- 354290 Amazon Linux Security Advisory for python-twisted : ALAS2022-2022-231
- 354525 Amazon Linux Security Advisory for python-twisted : ALAS2022-2022-046
- 354583 Amazon Linux Security Advisory for python-twisted : ALAS-2022-231
- 355118 Amazon Linux Security Advisory for python-twisted : ALAS2023-2023-056
- 502347 Alpine Linux Security Update for py3-twisted
- 710703 Gentoo Linux Twisted Multiple Vulnerabilities (GLSA 202301-02)
- 752235 SUSE Enterprise Linux Security Update for python-Twisted (SUSE-SU-2022:2070-1)
- 753149 SUSE Enterprise Linux Security Update for python-Twisted (SUSE-SU-2022:2297-1)