.NET Denial of Service Vulnerability
Published Feb 9, 2022
7.5
HIGHCVSS 3.1
EPSS 3.74%
Description
.NET Denial of Service Vulnerability
Affected products
- Vendor Microsoft Product Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) Defaultn/a
- Version 16.11.0StatusaffectedConstraints<16.11.10
- Version
- Vendor Microsoft Product Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8) Defaultn/a
- Version 15.0.0StatusaffectedConstraints<16.9.17
- Version
-
- Version 17.0.0StatusaffectedConstraints<17.0.6
- Version
-
- Version 8.1.0StatusaffectedConstraints<8.10.18
- Version
-
- Version 5.0.0StatusaffectedConstraints<5.0.14
- Version 6.0.0StatusaffectedConstraints<6.0.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) | n/a |
| |||||||||
| Microsoft | Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8) | n/a |
| |||||||||
| Microsoft | Microsoft Visual Studio 2022 version 17.0 | n/a |
| |||||||||
| Microsoft | Visual Studio 2019 for Mac version 8.10 | n/a |
| |||||||||
| Microsoft | n/a | n/a |
|
Configuration 1
- ≥ 5.0 · < 5.0.14
- ≥ 6.0.0 · < 6.0.2
- ≥ 8.10 · < 8.10.18
- ≥ 16.0 · ≤ 16.11
- ≥ 17.0 · < 17.0.6
Configuration 2
- 34
- 35
No data.
.NET Core on Red Hat Enterprise Linux
rh-dotnet50-dotnet-0:5.0.211-1.el7_9
Fixed · RHSA-2022:0499
.NET Core on Red Hat Enterprise Linux
rh-dotnet60-dotnet-0:6.0.102-1.el7_9
Fixed · RHSA-2022:0500
Red Hat Enterprise Linux 8
dotnet5.0-0:5.0.211-1.el8_5
Fixed · RHSA-2022:0495
Red Hat Enterprise Linux 8
dotnet6.0-0:6.0.102-1.el8_5
Fixed · RHSA-2022:0496
.NET Core 3.1 on Red Hat Enterprise Linux
rh-dotnet31
Not affected
Red Hat Enterprise Linux 8
dotnet3.1
Not affected
Red Hat Enterprise Linux 9
dotnet3.1
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core on Red Hat Enterprise Linux | rh-dotnet50-dotnet-0:5.0.211-1.el7_9 | Fixed | RHSA-2022:0499 |
| .NET Core on Red Hat Enterprise Linux | rh-dotnet60-dotnet-0:6.0.102-1.el7_9 | Fixed | RHSA-2022:0500 |
| Red Hat Enterprise Linux 8 | dotnet5.0-0:5.0.211-1.el8_5 | Fixed | RHSA-2022:0495 |
| Red Hat Enterprise Linux 8 | dotnet6.0-0:6.0.102-1.el8_5 | Fixed | RHSA-2022:0496 |
| .NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet3.1 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dotnet3.1 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-21986 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2051490 Issue Tracking
- https://github.com/advisories/GHSA-x459-p2rx-f8ff Advisory
- https://github.com/dotnet/announcements/issues/207
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-x459-p2rx-f8ff
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4HMQOHV7G5TF6OMBN6DNTDOKQQU7KHMM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CCTBSBE3PNIMXG6ALX2CQG4ZEH7W3YAT/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21986 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-21986
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21986
- https://www.cve.org/CVERecord?id=CVE-2022-21986
Change history (0)
No recorded changes yet.