CVE-2015-1822
published 2015-04-16CVE-2015-1822: chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated…
PriorityP432medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.96%
85.6th percentile
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chrony | < chrony 1.30-2 (bookworm) | chrony 1.30-2 (bookworm) |
| debian | debian_linux | — | — |
| tuxfamily | chrony | <= 1.31 | — |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
| tuxfamily | chrony | >= 0 < 1.30-2 | 1.30-2 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rchf-p2rm-hg6h: chrony before 1
ghsa_unreviewed·2022-05-17
CVE-2015-1822 [MEDIUM] GHSA-rchf-p2rm-hg6h: chrony before 1
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
OSV
CVE-2015-1822: chrony before 1
osv·2015-04-16·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822: chrony before 1
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
Red Hat
chrony: uninitialized pointer in cmdmon reply slots
vendor_redhat·2015-04-07·CVSS 6.5
CVE-2015-1822 [MEDIUM] CWE-456 chrony: uninitialized pointer in cmdmon reply slots
chrony: uninitialized pointer in cmdmon reply slots
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
An uninitialized pointer use flaw was found when allocating memory to save unacknowledged replies to authenticated command requests. An attacker that has the command key and is allowed to access cmdmon (only localhost is allowed by default) could use this flaw to crash chronyd or, possibly, execute arbitrary code with the privileges of the chronyd process.
Debian
CVE-2015-1822: chrony - chrony before 1.31.1 does not initialize the last "next" pointer when saving una...
vendor_debian·2015·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822: chrony - chrony before 1.31.1 does not initialize the last "next" pointer when saving una...
chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
Scope: local
bookworm: resolved (fixed in 1.30-2)
bullseye: resolved (fixed in 1.30-2)
forky: resolved (fixed in 1.30-2)
sid: resolved (fixed in 1.30-2)
trixie: resolved (fixed in 1.30-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [fedora-all]
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822 CVE-2015-1821 chrony: various flaws [fedora-all]
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
Bugzilla
CVE-2015-1822 chrony: uninitialized pointer in cmdmon reply slots
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822 chrony: uninitialized pointer in cmdmon reply slots
CVE-2015-1822 chrony: uninitialized pointer in cmdmon reply slots
Miroslav Lichvar of Red Hat reports:
The last pointer in the list of allocated reply slots that are used to
save authenticated cmdmon replies is not initialized.
This one was actually found couple months ago and it's already fixed
in git, but only recently I realized it could have security
implications.
An authenticated attacker can allocate and deallocate memory with
other commands (e.g. allow/deny) and can force allocation of new reply
slots by making new requests and not acknowledging previous replies,
and then let chronyd write a reply to an invalid memory.
Discussion:
Acknowledgements:
This issue was discovered by Miroslav Lichvár of Red Hat.
---
Created chrony tracking bugs for this issue:
Affects: epel-all [
Bugzilla
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [epel-all]
bugzilla·2015-04-07·CVSS 6.5
CVE-2015-1822 [MEDIUM] CVE-2015-1822 CVE-2015-1821 chrony: various flaws [epel-all]
CVE-2015-1822 CVE-2015-1821 chrony: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL.
http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-announce/2015/04/msg00002.htmlhttp://www.debian.org/security/2015/dsa-3222http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73956https://security.gentoo.org/glsa/201507-01http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-announce/2015/04/msg00002.htmlhttp://www.debian.org/security/2015/dsa-3222http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73956https://security.gentoo.org/glsa/201507-01
2015-04-16
Published