Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 864941 (CVE-2022-38150) - <www-servers/varnish-7.1.1: assertion failure via crafted request from backend
Summary: <www-servers/varnish-7.1.1: assertion failure via crafted request from backend
Status: RESOLVED FIXED
Alias: CVE-2022-38150
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://varnish-cache.org/security/VS...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 864991
Blocks:
  Show dependency tree
 
Reported: 2022-08-11 20:31 UTC by John Helmert III
Modified: 2022-08-14 16:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-11 20:31:10 UTC
CVE-2022-38150:

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

Pleaes bump to 7.1.1.
Comment 1 Anthony Basile gentoo-dev 2022-08-12 13:15:08 UTC
I just put 7.1.1 in the tree.  Preliminary test on amd64 suggests that its ready for rapid stabilization.  I'll open a bug now.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-13 23:21:23 UTC
Thanks!
Comment 3 Anthony Basile gentoo-dev 2022-08-14 15:24:57 UTC
(In reply to John Helmert III from comment #2)
> Thanks!

7.1.1 is fully stable and I've taken all vulnerable versions off the tree.
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-14 16:03:24 UTC
Thanks! Impact is very low since this requires a malicious backend, so no GLSA, all done!