Back

HIGH

NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory

Published Sep 13, 2018

Description

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Sep 13, 2018
Updated Aug 5, 2024
Reserved Mar 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 11, 2018
GHSA-J378-6MMW-HQFR