UBUNTU-CVE-2023-2253
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-2253
UBUNTU-CVE-2023-2253
Summary:
Details: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
References: https://ubuntu.com/security/CVE-2023-2253, https://github.com/distribution/distribution/commit/521ea3d973cb0c7089ebbcdd4ccadc34be941f54, https://www.openwall.com/lists/oss-security/2023/05/09/1, https://github.com/distribution/distribution/security/advisories/GHSA-hqxw-f8mx-cpmw, https://ubuntu.com/security/notices/USN-6336-1, https://www.cve.org/CVERecord?id=CVE-2023-2253
Affected packages
Package
Name: docker-registry
Purl: pkg:deb/ubuntu/[email protected]~ds1-1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
