VYPR
Medium severity6.5NVD Advisory· Published Nov 18, 2022· Updated Jun 17, 2026

CVE-2022-44641

CVE-2022-44641

Description

In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:linaro:lava:*:*:*:*:*:*:*:*
    Range: <2022.11
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • Linaro/Automated Validation Architecturedescription
  • Range: <2022.11

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.