CVE-2022-41556
Summary
| CVE | CVE-2022-41556 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-06 18:17:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Lighttpd: Denial of Service (GLSA 202210-12) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Comparing lighttpd-1.4.66...lighttpd-1.4.67 · lighttpd/lighttpd1.4 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: lighttpd-1.4.67-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [core] handle RDHUP when collecting chunked body · b18de6f926 - lighttpd1.4 - Gitea: git hosting on git.lighttpd.net |
MISC |
git.lighttpd.net |
|
| [core] release connections in CLOSE_WAIT & CON_STATE_READ_POST state by gmd20 · Pull Request #115 · lighttpd/lighttpd1.4 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: lighttpd-1.4.67-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181083 Debian Security Update for lighttpd (DSA 5243-1)
- 183019 Debian Security Update for lighttpd (CVE-2022-41556)
- 199198 Ubuntu Security Notification for lighttpd Vulnerabilities (USN-5903-1)
- 283176 Fedora Security Update for lighttpd (FEDORA-2022-c26b19568d)
- 502743 Alpine Linux Security Update for lighttpd
- 503685 Alpine Linux Security Update for lighttpd
- 710656 Gentoo Linux Lighttpd Denial of Service Vulnerability (GLSA 202210-12)