CVE-2022-4415

Severity
5.5MEDIUM
EPSS
0.0%
top 90.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateApr 15

Description

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDsystemd_project/systemd246253
Debiansystemd< 247.3-7+deb11u2+3
CVEListV5systemdsystemd >= 247

Patches

🔴Vulnerability Details

4
OSV
systemd vulnerabilities2023-03-07
GHSA
GHSA-x49m-v7mv-3wvx: A vulnerability was found in systemd2023-01-11
OSV
CVE-2022-4415: A vulnerability was found in systemd2023-01-11
CVEList
CVE-2022-4415: A vulnerability was found in systemd2023-01-11

📋Vendor Advisories

5
Oracle
Oracle Oracle Communications Risk Matrix: Policy (systemd) — CVE-2022-44152023-04-15
Ubuntu
systemd vulnerabilities2023-03-07
Microsoft
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.2023-01-10
Red Hat
systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting2022-12-21
Debian
CVE-2022-4415: systemd - A vulnerability was found in systemd. This security flaw can cause a local infor...2022