CVE-2022-1304
published 2022-04-14CVE-2022-1304: An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.38%
69.3th percentile
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_hypervisor | — | — |
| citrix | xenserver | — | — |
| debian | e2fsprogs | < e2fsprogs 1.46.6~rc1-1 (bookworm) | e2fsprogs 1.46.6~rc1-1 (bookworm) |
| e2fsprogs_project | e2fsprogs | — | — |
| e2fsprogs_project | e2fsprogs | — | — |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.46.2-2+deb11u1 | 1.46.2-2+deb11u1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.46.6~rc1-1 | 1.46.6~rc1-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.46.6~rc1-1 | 1.46.6~rc1-1 |
| e2fsprogs_project | e2fsprogs | >= 0 < 1.46.6~rc1-1 | 1.46.6~rc1-1 |
| fedoraproject | fedora | — | — |
| msrc | cbl2_e2fsprogs_1.46.5-3_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Citrix Hypervisor Multiple Security Updates
vendor_citrix·2023-10-10·CVSS 7.8
CVE-2022-1304 [HIGH] Citrix Hypervisor Multiple Security Updates
Citrix Hypervisor Multiple Security Updates
of Problem Several issues have been discovered that affect Citrix Hypervisor 8.2 CU1 LTSR and may allow malicious privileged code in a guest VM to: i) Compromise an AMD-based host via a passed through PCI device: CVE-2023-34326 ii) Compromise the host when a specific administrative action is taken (see
CVE References: CVE-2022-1304, CVE-2023-20588, CVE-2023-34324, CVE-2023-34326, CVE-2023-34327
Affected Products: Citrix Hypervisor, XenServer
Severity: High
Remediation:
We have released hotfixes to address these issues. We recommend that affected customers install these hotfixes and follow the instructions in the linked articles as their update schedule permits. The hotfixes can be downloaded from the following locations: CTX575070 - https://su
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Oracle
Oracle Oracle Communications Risk Matrix: Oracle Linux (e2fsprogs) — CVE-2022-1304
vendor_oracle·2023-01-15·CVSS 7.8
CVE-2022-1304 [HIGH] Oracle Oracle Communications Risk Matrix: Oracle Linux (e2fsprogs) — CVE-2022-1304
Oracle Oracle Communications Risk Matrix: Oracle Linux (e2fsprogs) vulnerability
CVE: CVE-2022-1304
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
Ubuntu
e2fsprogs vulnerability
vendor_ubuntu·2022-06-07
CVE-2022-1304 e2fsprogs vulnerability
Title: e2fsprogs vulnerability
Summary: e2fsprogs could be made to crash or possibly run programs if it processed
a specially crafted file system image.
Nils Bars discovered that e2fsprogs incorrectly handled certain file
systems. A local attacker could use this issue with a crafted file
system image to possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
vendor_msrc·2022-04-12·CVSS 7.8
CVE-2022-1304 [HIGH] CWE-125 An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to refle
Red Hat
e2fsprogs: out-of-bounds read/write via crafted filesystem
vendor_redhat·2022-03-24·CVSS 7.8
CVE-2022-1304 [HIGH] CWE-787 e2fsprogs: out-of-bounds read/write via crafted filesystem
e2fsprogs: out-of-bounds read/write via crafted filesystem
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
An out-of-bounds read/write vulnerability was found in e2fsprogs. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Package: e2fsprogs (Red Hat Enterprise Linux 6) - Out of support scope
Package: e2fsprogs (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2022-1304: e2fsprogs - An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This is...
vendor_debian·2022·CVSS 7.8
CVE-2022-1304 [HIGH] CVE-2022-1304: e2fsprogs - An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This is...
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Scope: local
bookworm: resolved (fixed in 1.46.6~rc1-1)
bullseye: resolved (fixed in 1.46.2-2+deb11u1)
forky: resolved (fixed in 1.46.6~rc1-1)
sid: resolved (fixed in 1.46.6~rc1-1)
trixie: resolved (fixed in 1.46.6~rc1-1)
GHSA
GHSA-jrv4-gggm-r53c: An out-of-bounds read/write vulnerability was found in e2fsprogs 1
ghsa_unreviewed·2022-04-15
CVE-2022-1304 [HIGH] CWE-125 GHSA-jrv4-gggm-r53c: An out-of-bounds read/write vulnerability was found in e2fsprogs 1
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
OSV
CVE-2022-1304: An out-of-bounds read/write vulnerability was found in e2fsprogs 1
osv·2022-04-14·CVSS 7.8
CVE-2022-1304 [HIGH] CVE-2022-1304: An out-of-bounds read/write vulnerability was found in e2fsprogs 1
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-14
Published