CVE-2022-24795
Summary
| CVE | CVE-2022-24795 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-05 16:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf->alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL. |
Risk And Classification
Problem Types: CWE-190 | CWE-122
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yajl-ruby Project | Yajl-ruby | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 38 Update: yajl-2.1.0-21.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: yajl-2.1.0-21.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: yajl-2.1.0-21.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Merge pull request #204 from eileencodes/fix-c-warnings · brianmario/yajl-ruby@7168bd7 · GitHub | MISC | github.com | |
| Reallocation bug can trigger heap memory corruption · Advisory · brianmario/yajl-ruby · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 37 Update: yajl-2.1.0-21.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] [DLA 3492-1] yajl security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 3516-1] burp security update | MLIST | lists.debian.org | |
| yajl-ruby/yajl_buf.c at 7168bd79b888900aa94523301126f968a93eb3a6 · brianmario/yajl-ruby · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160247 Oracle Enterprise Linux Security Update for yajl (ELSA-2022-7524)
- 160291 Oracle Enterprise Linux Security Update for yajl (ELSA-2022-8252)
- 184196 Debian Security Update for ruby-yajl (CVE-2022-24795)
- 199554 Ubuntu Security Notification for YAJL Vulnerabilities (USN-6233-1)
- 200011 Ubuntu Security Notification for YAJL Vulnerabilities (USN-6233-2)
- 240836 Red Hat Update for yajl (RHSA-2022:7524)
- 240907 Red Hat Update for yajl (RHSA-2022:8252)
- 284318 Fedora Security Update for yajl (FEDORA-2023-00572178e1)
- 284354 Fedora Security Update for yajl (FEDORA-2023-852b377773)
- 355555 Amazon Linux Security Advisory for yajl : ALAS2-2023-2101
- 355644 Amazon Linux Security Advisory for yajl : ALAS2023-2023-263
- 6000034 Debian Security Update for burp (DLA 3516-1)
- 671722 EulerOS Security Update for yajl (EulerOS-SA-2022-1776)
- 671834 EulerOS Security Update for yajl (EulerOS-SA-2022-1919)
- 672332 EulerOS Security Update for yajl (EulerOS-SA-2022-2786)
- 672357 EulerOS Security Update for yajl (EulerOS-SA-2022-2751)
- 672420 EulerOS Security Update for yajl (EulerOS-SA-2022-2812)
- 672433 EulerOS Security Update for yajl (EulerOS-SA-2022-2837)
- 672449 EulerOS Security Update for yajl (EulerOS-SA-2022-2863)
- 752161 SUSE Enterprise Linux Security Update for libyajl (SUSE-SU-2022:1746-1)
- 752560 SUSE Enterprise Linux Security Update for libyajl (SUSE-SU-2022:3162-1)
- 900813 Common Base Linux Mariner (CBL-Mariner) Security Update for rubygem-yajl-ruby (9344)
- 901350 Common Base Linux Mariner (CBL-Mariner) Security Update for rubygem-yajl-ruby (9344-1)
- 902748 Common Base Linux Mariner (CBL-Mariner) Security Update for rubygem-yajl-ruby (10552)
- 903928 Common Base Linux Mariner (CBL-Mariner) Security Update for rubygem-yajl-ruby (10552-1)
- 940753 AlmaLinux Security Update for yajl (ALSA-2022:7524)
- 940835 AlmaLinux Security Update for yajl (ALSA-2022:8252)
- 960281 Rocky Linux Security Update for yajl (RLSA-2022:7524)
- 960497 Rocky Linux Security Update for yajl (RLSA-2022:8252)