CVE-2022-2529

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.

The high-scalability sFlow/NetFlow/IPFIX collector used internally at Cloudflare.
GitHubGitHub
919