Multiple DoS Attack Vectors in sflow packet handling
CVE-2022-2529
7.5HIGH
What is CVE-2022-2529?
sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.
Affected Version(s)
goflow Go < 3.4.4