CVE-2022-4415
published 2023-01-11CVE-2022-4415: A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.87%
55.0th percentile
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 252.4-1 (bookworm) | systemd 252.4-1 (bookworm) |
| msrc | azl3_systemd-bootstrap_250.3-15_on_azure_linux_3.0 | — | — |
| msrc | azl3_systemd-bootstrap_250.3-17_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_systemd-bootstrap_250.3-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_systemd_250.3-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_systemd_239-43_on_cbl_mariner_1.0 | — | — |
| systemd_project | systemd | — | — |
| systemd_project | systemd | >= 0 < 247.3-7+deb11u2 | 247.3-7+deb11u2 |
| systemd_project | systemd | >= 0 < 252.4-1 | 252.4-1 |
| systemd_project | systemd | >= 0 < 252.4-1 | 252.4-1 |
| systemd_project | systemd | >= 0 < 252.4-1 | 252.4-1 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.57 | 237-3ubuntu10.57 |
| systemd_project | systemd | >= 0 < 245.4-4ubuntu3.20 | 245.4-4ubuntu3.20 |
| systemd_project | systemd | >= 0 < 249.11-0ubuntu3.7 | 249.11-0ubuntu3.7 |
| systemd_project | systemd | >= 0 < 204-5ubuntu20.31+esm2 | 204-5ubuntu20.31+esm2 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm3 | 229-4ubuntu21.31+esm3 |
| systemd_project | systemd | >= 246 < 253 | 253 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
systemd vulnerabilities
osv·2023-03-07·CVSS 5.5
CVE-2022-3821 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd did not properly validate the time and
accuracy values provided to the format_timespan() function. An attacker
could possibly use this issue to cause a buffer overrun, leading to a
denial of service attack. This issue only affected Ubuntu 14.04 ESM, Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3821)
It was discovered that systemd did not properly manage the fs.suid_dumpable
kernel configurations. A local attacker could possibly use this issue to
expose sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-4415)
It was discovered that systemd did not properly manage a crash with long
backtrace data. A local attacker could possibly use t
GHSA
GHSA-x49m-v7mv-3wvx: A vulnerability was found in systemd
ghsa_unreviewed·2023-01-11
CVE-2022-4415 [MEDIUM] CWE-200 GHSA-x49m-v7mv-3wvx: A vulnerability was found in systemd
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
OSV
CVE-2022-4415: A vulnerability was found in systemd
osv·2023-01-11·CVSS 5.5
CVE-2022-4415 [MEDIUM] CVE-2022-4415: A vulnerability was found in systemd
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Oracle
Oracle Oracle Communications Risk Matrix: Policy (systemd) — CVE-2022-4415
vendor_oracle·2023-04-15·CVSS 5.5
CVE-2022-4415 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (systemd) — CVE-2022-4415
Oracle Oracle Communications Risk Matrix: Policy (systemd) vulnerability
CVE: CVE-2022-4415
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2023-03-07·CVSS 5.5
CVE-2022-3821 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd did not properly validate the time and
accuracy values provided to the format_timespan() function. An attacker
could possibly use this issue to cause a buffer overrun, leading to a
denial of service attack. This issue only affected Ubuntu 14.04 ESM, Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3821)
It was discovered that systemd did not properly manage the fs.suid_dumpable
kernel configurations. A local attacker could possibly use this issue to
expose sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-4415)
It was discovered that systemd did not properly manage a crash
Microsoft
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
vendor_msrc·2023-01-10·CVSS 5.5
CVE-2022-4415 [MEDIUM] CWE-200 A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: M
Red Hat
systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting
vendor_redhat·2022-12-21·CVSS 5.5
CVE-2022-4415 [MEDIUM] CWE-200 systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting
systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Package: NetworkManager (Red Hat Enterprise Linux 7) - Out of support scope
Package: systemd (Red Hat Enterprise Linux 7) - Out of support scope
Package: NetworkManager (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-4415: systemd - A vulnerability was found in systemd. This security flaw can cause a local infor...
vendor_debian·2022·CVSS 5.5
CVE-2022-4415 [MEDIUM] CVE-2022-4415: systemd - A vulnerability was found in systemd. This security flaw can cause a local infor...
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.
Scope: local
bookworm: resolved (fixed in 252.4-1)
bullseye: resolved (fixed in 247.3-7+deb11u2)
forky: resolved (fixed in 252.4-1)
sid: resolved (fixed in 252.4-1)
trixie: resolved (fixed in 252.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9chttps://www.openwall.com/lists/oss-security/2022/12/21/3http://seclists.org/fulldisclosure/2025/Jun/9https://github.com/systemd/systemd/commit/b7641425659243c09473cd8fb3aef2c0d4a3eb9chttps://security.netapp.com/advisory/ntap-20230216-0010/https://www.openwall.com/lists/oss-security/2022/12/21/3
2023-01-11
Published