NULL Pointer Dereference Affecting olcne-api-server package, versions <0:1.5.4-3.el8


Severity

Recommended
high

Based on Oracle Linux security rating.

Threat Intelligence

EPSS
0.09% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-ORACLE8-OLCNEAPISERVER-2946826
  • published12 Jul 2022
  • disclosed9 Jun 2022

Introduced: 9 Jun 2022

CVE-2022-29224  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade Oracle:8 olcne-api-server to version 0:1.5.4-3.el8 or higher.
This issue was patched in ELSA-2022-9588.

NVD Description

Note: Versions mentioned in the description apply only to the upstream olcne-api-server package and not the olcne-api-server package as distributed by Oracle. See How to fix? for Oracle:8 relevant fixed versions and status.

Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a feature which can “hold” (prevent removal) upstream hosts obtained via service discovery until configured active health checking fails. If an attacker controls an upstream host and also controls service discovery of that host (via DNS, the EDS API, etc.), an attacker can crash Envoy by forcing removal of the host from service discovery, and then failing the gRPC health check request. This will crash Envoy via a null pointer dereference. Users are advised to upgrade to resolve this vulnerability. Users unable to upgrade may disable gRPC health checking and/or replace it with a different health checking type as a mitigation.

CVSS Scores

version 3.1