← Voltar para CVEs
CVE-2022-45873
MEDIUM5.5
Descricao
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Detalhes CVE
Pontuacao CVSS v3.15.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado11/23/2022
Ultima modificacao4/25/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
fedoraproject:fedorasystemd_project:systemd
Fraquezas (CWE)
CWE-400CWE-400
Referencias
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/(cve@mitre.org)
https://github.com/systemd/systemd/commit/076b807be472630692c5348c60d0c2b7b28ad437(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/systemd/systemd/pull/24853#issuecomment-1326561497(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/systemd/systemd/pull/25055#issuecomment-1313733553(af854a3a-2127-422b-91ae-364da2661108)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.