Description
A vulnerability was found in dotnet’s ASP.NET Core Krestel when pooling HTTP/2 and HTTP/3 headers. This flaw allows a remote, unauthenticated attacker to cause a denial of service.
Solution(s)
redhat-upgrade-aspnetcore-runtime-6-0redhat-upgrade-aspnetcore-targeting-pack-6-0redhat-upgrade-dotnetredhat-upgrade-dotnet-apphost-pack-6-0redhat-upgrade-dotnet-apphost-pack-6-0-debuginforedhat-upgrade-dotnet-hostredhat-upgrade-dotnet-host-debuginforedhat-upgrade-dotnet-hostfxr-6-0redhat-upgrade-dotnet-hostfxr-6-0-debuginforedhat-upgrade-dotnet-runtime-6-0redhat-upgrade-dotnet-runtime-6-0-debuginforedhat-upgrade-dotnet-sdk-6-0redhat-upgrade-dotnet-sdk-6-0-debuginforedhat-upgrade-dotnet-targeting-pack-6-0redhat-upgrade-dotnet-templates-6-0redhat-upgrade-dotnet6-0-debuginforedhat-upgrade-dotnet6-0-debugsourceredhat-upgrade-netstandard-targeting-pack-2-1
ReferencesCVE-2022-219862RHSA-2022:0496