CVE-2022-36227
published 2022-11-22CVE-2022-36227: In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.94%
77.8th percentile
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libarchive | < libarchive 3.6.2-1 (bookworm) | libarchive 3.6.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libarchive | libarchive | >= 0 < 3.4.3-2+deb11u2 | 3.4.3-2+deb11u2 |
| libarchive | libarchive | >= 0 < 3.6.2-1 | 3.6.2-1 |
| libarchive | libarchive | >= 0 < 3.6.2-1 | 3.6.2-1 |
| libarchive | libarchive | >= 0 < 3.6.2-1 | 3.6.2-1 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.3 | 3.4.0-2ubuntu1.3 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.2 | 3.6.0-1ubuntu1.2 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.2 | 3.7.2-2ubuntu0.2 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm3 | 3.1.2-7ubuntu2.8+esm3 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm1 | 3.1.2-11ubuntu0.16.04.8+esm1 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm1 | 3.2.2-3.1ubuntu0.7+esm1 |
| libarchive | libarchive | >= 3.0.0 < 3.6.2 | 3.6.2 |
| msrc | cbl2_libarchive_3.6.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libarchive_3.6.1-2_on_cbl_mariner_1.0 | — | — |
| splunk | universal_forwarder | — | — |
| splunk | universal_forwarder | >= 8.2.0 < 8.2.12 | 8.2.12 |
| splunk | universal_forwarder | >= 9.0.0 < 9.0.6 | 9.0.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libarchive vulnerabilities
osv·2024-10-16·CVSS 9.8
CVE-2022-36227 [CRITICAL] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive mishandled certain memory checks,
which could result in a NULL pointer dereference. An attacker could
potentially use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227)
It was discovered that libarchive mishandled certain memory operations,
which could result in an out-of-bounds memory access. An attacker could
potentially use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-48957, CVE-2024-48958)
GHSA
GHSA-gpgf-w78r-4pvj: In libarchive 3
ghsa_unreviewed·2022-11-22
CVE-2022-36227 [CRITICAL] CWE-476 GHSA-gpgf-w78r-4pvj: In libarchive 3
In libarchive 3.6.1, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference or, in some cases, even arbitrary code execution.
OSV
CVE-2022-36227: In libarchive before 3
osv·2022-11-22·CVSS 9.8
CVE-2022-36227 [CRITICAL] CVE-2022-36227: In libarchive before 3
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2024-10-16·CVSS 9.8
CVE-2024-48958 [CRITICAL] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: Several security issues were fixed in libarchive.
It was discovered that libarchive mishandled certain memory checks,
which could result in a NULL pointer dereference. An attacker could
potentially use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227)
It was discovered that libarchive mishandled certain memory operations,
which could result in an out-of-bounds memory access. An attacker could
potentially use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-48957, CVE-2024-48958)
Instructions: In general, a standard system update will make all the necessar
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Microsoft
In libarchive before 3.6.2 the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails which leads to a resultant NULL pointer dere
vendor_msrc·2022-11-08·CVSS 9.8
CVE-2022-36227 [CRITICAL] CWE-476 In libarchive before 3.6.2 the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails which leads to a resultant NULL pointer dere
In libarchive before 3.6.2 the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances when NULL is equivalent to the 0x0 memory address and privileged code can access it then writing or reading memory is possible which may lead to code execution."
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secur
Red Hat
libarchive: NULL pointer dereference in archive_write.c
vendor_redhat·2022-07-11·CVSS 9.8
CVE-2022-36227 [CRITICAL] CWE-476 libarchive: NULL pointer dereference in archive_write.c
libarchive: NULL pointer dereference in archive_write.c
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
A flaw was found in libarchive. A missing check of the return value of the calloc function can cause a NULL pointer dereference in an out-of-memory condition or when a memory allocation limit is reached, resulting in the program linked with li
Debian
CVE-2022-36227: libarchive - In libarchive before 3.6.2, the software does not check for an error after calli...
vendor_debian·2022·CVSS 9.8
CVE-2022-36227 [CRITICAL] CVE-2022-36227: libarchive - In libarchive before 3.6.2, the software does not check for an error after calli...
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
Scope: local
bookworm: resolved (fixed in 3.6.2-1)
bullseye: resolved (fixed in 3.4.3-2+deb11u2)
forky: resolved (fixed in 3.6.2-1)
sid: resolved (fixed in 3.6.2-1)
trixie: resolved (fixed in 3.6.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.gentoo.org/882521https://github.com/libarchive/libarchive/blob/v3.0.0a/libarchive/archive_write.c#L215https://github.com/libarchive/libarchive/issues/1754https://lists.debian.org/debian-lts-announce/2023/01/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/https://security.gentoo.org/glsa/202309-14https://bugs.gentoo.org/882521https://github.com/libarchive/libarchive/blob/v3.0.0a/libarchive/archive_write.c#L215https://github.com/libarchive/libarchive/issues/1754https://lists.debian.org/debian-lts-announce/2023/01/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2024/11/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V67OO2UUQAUJS3IK4JZPF6F3LUCBU6IS/https://security.gentoo.org/glsa/202309-14
2022-11-22
Published