High severityNVD Advisory· Published Jul 24, 2022· Updated Aug 3, 2024
ReDoS in Apache MXNet RTC Module
CVE-2022-24294
Description
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular expression evaluation to use excessive resources to attempt a match. This issue affects Apache MXNet versions prior to 1.9.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mxnetPyPI | < 1.9.1 | 1.9.1 |
Affected products
3- osv-coords2 versions
< 1.9.1+ 1 more
- (no CPE)range: < 1.9.1
- (no CPE)range: < 1.9.1
- Apache Software Foundation/Apache MXNetv5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-xxj3-55p6-xg3hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24294ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/07/24/2ghsamailing-listx_refsource_MLISTWEB
- github.com/apache/mxnet/releases/tag/1.9.1ghsaWEB
- lists.apache.org/thread/b1fbfmvzlr2bbp95lqoh3mtovclfcl3oghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.