CVE-2022-45873
published 2022-11-23CVE-2022-45873: systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 252-1 (bookworm) | systemd 252-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | azl3_systemd-bootstrap_250.3-17_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| systemd_project | systemd | — | — |
| systemd_project | systemd | >= 0 < 252-1 | 252-1 |
| systemd_project | systemd | >= 0 < 252-1 | 252-1 |
| systemd_project | systemd | >= 0 < 252-1 | 252-1 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.57 | 237-3ubuntu10.57 |
| systemd_project | systemd | >= 0 < 245.4-4ubuntu3.20 | 245.4-4ubuntu3.20 |
| systemd_project | systemd | >= 0 < 249.11-0ubuntu3.7 | 249.11-0ubuntu3.7 |
| systemd_project | systemd | >= 0 < 204-5ubuntu20.31+esm2 | 204-5ubuntu20.31+esm2 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm3 | 229-4ubuntu21.31+esm3 |
| systemd_project | systemd | 250 – 251 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
systemd vulnerabilities
osv·2023-03-07·CVSS 5.5
CVE-2022-3821 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd did not properly validate the time and
accuracy values provided to the format_timespan() function. An attacker
could possibly use this issue to cause a buffer overrun, leading to a
denial of service attack. This issue only affected Ubuntu 14.04 ESM, Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3821)
It was discovered that systemd did not properly manage the fs.suid_dumpable
kernel configurations. A local attacker could possibly use this issue to
expose sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-4415)
It was discovered that systemd did not properly manage a crash with long
backtrace data. A local attacker could possibly use t
GHSA
GHSA-3w8w-mhj7-j5rc: systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace
ghsa_unreviewed·2022-11-24
CVE-2022-45873 [MEDIUM] CWE-400 GHSA-3w8w-mhj7-j5rc: systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
OSV
CVE-2022-45873: systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace
osv·2022-11-23·CVSS 5.5
CVE-2022-45873 [MEDIUM] CVE-2022-45873: systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2023-03-07·CVSS 5.5
CVE-2022-3821 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd did not properly validate the time and
accuracy values provided to the format_timespan() function. An attacker
could possibly use this issue to cause a buffer overrun, leading to a
denial of service attack. This issue only affected Ubuntu 14.04 ESM, Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3821)
It was discovered that systemd did not properly manage the fs.suid_dumpable
kernel configurations. A local attacker could possibly use this issue to
expose sensitive information. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-4415)
It was discovered that systemd did not properly manage a crash
Microsoft
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation me
vendor_msrc·2022-11-08·CVSS 5.5
CVE-2022-45873 [MEDIUM] CWE-400 systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation me
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the
Red Hat
systemd: deadlock in systemd-coredump via a crash with a long backtrace
vendor_redhat·2022-10-18·CVSS 5.5
CVE-2022-45873 [MEDIUM] CWE-833 systemd: deadlock in systemd-coredump via a crash with a long backtrace
systemd: deadlock in systemd-coredump via a crash with a long backtrace
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
A flaw was found in the systemd-coredump utility of systemd. When an application crashes, the systemd-coredump utility is called twice, once by the kernel and the second time in the [email protected] to write the data, process, and save the
Debian
CVE-2022-45873: systemd - systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by...
vendor_debian·2022·CVSS 5.5
CVE-2022-45873 [MEDIUM] CVE-2022-45873: systemd - systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by...
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Scope: local
bookworm: resolved (fixed in 252-1)
bullseye: resolved
forky: resolved (fixed in 252-1)
sid: resolved (fixed in 252-1)
trixie: resolved (fixed in 252-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/systemd/systemd/commit/076b807be472630692c5348c60d0c2b7b28ad437https://github.com/systemd/systemd/pull/24853#issuecomment-1326561497https://github.com/systemd/systemd/pull/25055#issuecomment-1313733553https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/https://github.com/systemd/systemd/commit/076b807be472630692c5348c60d0c2b7b28ad437https://github.com/systemd/systemd/pull/24853#issuecomment-1326561497https://github.com/systemd/systemd/pull/25055#issuecomment-1313733553https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/
2022-11-23
Published