Skip to content

Multiple DoS Attack Vectors in sflow packet handling

Moderate
mskowroncf published GHSA-9rpw-2h95-666c Sep 30, 2022

Package

gomod github.com/cloudflare/goflow (Go)

Affected versions

< 3.4.4

Patched versions

3.4.4

Description

Impact

sflow decode package is vulnerable to a denial of service attack. Attackers can craft malformed packets causing the process to consume huge amounts of memory resulting in a denial of service.

Patches

Version 3.4.4 contains patches fixing this.

Workarounds

A possible workaround is to not have your goflow collector publicly reachable.

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-2529

Weaknesses

No CWEs

Credits