PT-2022-19442 · Pion Dtls+2 · Pion Dtls+2

Juho Nurminen

·

Published

2022-05-20

·

Updated

2026-01-19

·

CVE-2022-29190

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pion DTLS versions prior to 2.1.4
Description An attacker can send packets that will send Pion DTLS into an infinite loop when processing. This issue affects the DTLS server or client.
Recommendations For versions prior to 2.1.4, upgrade to Pion DTLS version 2.1.4 to resolve the issue. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2022-29190
GHSA-CM8F-H6J3-P25C
GO-2022-0460
USN-7966-1
USN-7966-2

Affected Products

Linuxmint
Pion Dtls
Ubuntu