Bareos Director versions prior to 21.1.0, 20.0.6, and 19.2.12 are affected by a memory leak vulnerability. This high severity issue can lead to denial of service due to out-of-memory conditions. Learn how to mitigate CVE-2022-24756.
Bareos Director versions prior to 21.1.0, 20.0.6, and 19.2.12 are prone to a memory leak vulnerability when configured for PAM authentication, which can lead to denial of service. Learn more about the impact, technical details, and mitigation of CVE-2022-24756.
Understanding CVE-2022-24756
CVE-2022-24756 is a vulnerability found in Bareos Director versions prior to 21.1.0, 20.0.6, and 19.2.12 that can be exploited to cause an out-of-memory condition through a flood of failing login attempts.
What is CVE-2022-24756?
Bareos Director software, when configured for PAM authentication, may leak memory upon failed authentication attempts, potentially leading to a denial of service if attackers flood the system with such attempts.
The Impact of CVE-2022-24756
The vulnerability has a CVSS base score of 7.5, indicating a high severity issue that can cause the Director to stop working due to an out-of-memory condition.
Technical Details of CVE-2022-24756
Below are the technical details related to the CVE-2022-24756 vulnerability:
Vulnerability Description
When a Bareos Director version prior to 21.1.0, 20.0.6, or 19.2.12 is set up with PAM authentication, failed login attempts can exhaust memory resources, causing the service to fail.
Affected Systems and Versions
Exploitation Mechanism
An attacker with access to the PAM Console can flood the system with failing login attempts, triggering an out-of-memory condition.
Mitigation and Prevention
To address CVE-2022-24756, consider the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates