CVE-2022-3821
published 2022-11-08CVE-2022-3821: An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.4th percentile
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 251.3-1 (bookworm) | systemd 251.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | azl3_systemd-bootstrap_250.3-17_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_systemd_250.3-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_systemd_239-43_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| systemd_project | systemd | <= 251 | — |
| systemd_project | systemd | — | — |
| systemd_project | systemd | >= 0 < 247.3-7+deb11u2 | 247.3-7+deb11u2 |
| systemd_project | systemd | >= 0 < 251.3-1 | 251.3-1 |
| systemd_project | systemd | >= 0 < 251.3-1 | 251.3-1 |
| systemd_project | systemd | >= 0 < 251.3-1 | 251.3-1 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.57 | 237-3ubuntu10.57 |
| systemd_project | systemd | >= 0 < 245.4-4ubuntu3.20 | 245.4-4ubuntu3.20 |
| systemd_project | systemd | >= 0 < 249.11-0ubuntu3.7 | 249.11-0ubuntu3.7 |
| systemd_project | systemd | >= 0 < 204-5ubuntu20.31+esm2 | 204-5ubuntu20.31+esm2 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm3 | 229-4ubuntu21.31+esm3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
systemd vulnerabilities
osv·2023-03-07·CVSS 5.5
CVE-2022-3821 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd did not properly validate the time and
accuracy values provided to the format_timespan() function. An attacker
could possibly use this issue to cause a buffer overrun, leading to a
denial of service attack. This issue only affected Ubuntu 14.04 ESM, Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3821)
It was discovered that systemd did not properly manage the fs.suid_dumpable
kernel configurations. A local attacker could possibly use this issue to
expose sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-4415)
It was discovered that systemd did not properly manage a crash with long
backtrace data. A local attacker could possibly use t
GHSA
GHSA-cwpv-5v9v-5797: An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util
ghsa_unreviewed·2022-11-09
CVE-2022-3821 [MEDIUM] CWE-193 GHSA-cwpv-5v9v-5797: An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
OSV
CVE-2022-3821: An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util
osv·2022-11-08·CVSS 5.5
CVE-2022-3821 [MEDIUM] CVE-2022-3821: An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2023-03-07·CVSS 5.5
CVE-2022-3821 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd did not properly validate the time and
accuracy values provided to the format_timespan() function. An attacker
could possibly use this issue to cause a buffer overrun, leading to a
denial of service attack. This issue only affected Ubuntu 14.04 ESM, Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3821)
It was discovered that systemd did not properly manage the fs.suid_dumpable
kernel configurations. A local attacker could possibly use this issue to
expose sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-4415)
It was discovered that systemd did not properly manage a crash
Microsoft
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_
vendor_msrc·2022-11-08·CVSS 5.5
CVE-2022-3821 [MEDIUM] CWE-193 An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan() leading to a Denial of Service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional
Red Hat
systemd: buffer overrun in format_timespan() function
vendor_redhat·2022-07-08·CVSS 5.5
CVE-2022-3821 [MEDIUM] CWE-193 systemd: buffer overrun in format_timespan() function
systemd: buffer overrun in format_timespan() function
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
An off-by-one error flaw was found in systemd in the format_timespan() function of time-util.c. This flaw allows an attacker to supply specific values for time and accuracy, leading to a buffer overrun in format_timespan(), leading to a denial of service.
Statement: Network Manager uses systemd's format_timespan() only via the FORMAT_TIMESPAN() macro which allocates a 64-byte buffer on the stack.
The longest string representing 32bit values in seconds doesn't exceed 34 bytes (for example, "134y
Debian
CVE-2022-3821: systemd - An off-by-one Error issue was discovered in Systemd in format_timespan() functio...
vendor_debian·2022·CVSS 5.5
CVE-2022-3821 [MEDIUM] CVE-2022-3821: systemd - An off-by-one Error issue was discovered in Systemd in format_timespan() functio...
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Scope: local
bookworm: resolved (fixed in 251.3-1)
bullseye: resolved (fixed in 247.3-7+deb11u2)
forky: resolved (fixed in 251.3-1)
sid: resolved (fixed in 251.3-1)
trixie: resolved (fixed in 251.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2139327https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4ehttps://github.com/systemd/systemd/issues/23928https://github.com/systemd/systemd/pull/23933https://lists.debian.org/debian-lts-announce/2023/06/msg00036.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/https://security.gentoo.org/glsa/202305-15https://bugzilla.redhat.com/show_bug.cgi?id=2139327https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4ehttps://github.com/systemd/systemd/issues/23928https://github.com/systemd/systemd/pull/23933https://lists.debian.org/debian-lts-announce/2023/06/msg00036.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/https://security.gentoo.org/glsa/202305-15
2022-11-08
Published