CVE-2022-36227
Summary
| CVE | CVE-2022-36227 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-22 02:15:00 UTC |
| Updated | 2024-03-27 16:04:00 UTC |
| Description | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution." |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: libarchive-3.6.1-3.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| There is a NULL pointer dereference vulnerability · Issue #1754 · libarchive/libarchive · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 3294-1] libarchive security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 37 Update: libarchive-3.6.1-3.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| libarchive: Multiple Vulnerabilities (GLSA 202309-14) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| libarchive/archive_write.c at v3.0.0a · libarchive/libarchive · GitHub |
MISC |
github.com |
|
| 882521 – (CVE-2022-36227) app-arch/libarchive: null pointer dereference |
MISC |
bugs.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160605 Oracle Enterprise Linux Security Update for libarchive (ELSA-2023-2532)
- 160675 Oracle Enterprise Linux Security Update for libarchive (ELSA-2023-3018)
- 181531 Debian Security Update for libarchive (DLA 3294-1)
- 184855 Debian Security Update for libarchive (CVE-2022-36227)
- 241427 Red Hat Update for libarchive (RHSA-2023:2532)
- 241480 Red Hat Update for libarchive (RHSA-2023:3018)
- 242686 Red Hat Update for libarchive (RHSA-2024:0146)
- 283538 Fedora Security Update for libarchive (FEDORA-2022-e15be0091f)
- 355621 Amazon Linux Security Advisory for libarchive : ALAS2023-2023-246
- 356413 Amazon Linux Security Advisory for libarchive : ALAS2-2023-2279
- 356758 Amazon Linux Security Advisory for libarchive : ALAS2-2023-2364
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502604 Alpine Linux Security Update for libarchive
- 502605 Alpine Linux Security Update for libarchive
- 502734 Alpine Linux Security Update for libarchive
- 505625 Alpine Linux Security Update for libarchive
- 672589 EulerOS Security Update for libarchive (EulerOS-SA-2023-1322)
- 672644 EulerOS Security Update for libarchive (EulerOS-SA-2023-1361)
- 672645 EulerOS Security Update for libarchive (EulerOS-SA-2023-1389)
- 672696 EulerOS Security Update for libarchive (EulerOS-SA-2023-1426)
- 672700 EulerOS Security Update for libarchive (EulerOS-SA-2023-1411)
- 672729 EulerOS Security Update for libarchive (EulerOS-SA-2023-1446)
- 672757 EulerOS Security Update for libarchive (EulerOS-SA-2023-1471)
- 673083 EulerOS Security Update for libarchive (EulerOS-SA-2023-2154)
- 710757 Gentoo Linux libarchive Multiple Vulnerabilities (GLSA 202309-14)
- 752822 SUSE Enterprise Linux Security Update for libarchive (SUSE-SU-2022:4209-1)
- 752888 SUSE Enterprise Linux Security Update for libarchive (SUSE-SU-2022:4202-1)
- 752936 SUSE Enterprise Linux Security Update for libarchive (SUSE-SU-2022:4296-1)
- 904559 Common Base Linux Mariner (CBL-Mariner) Security Update for libarchive (11473)
- 904561 Common Base Linux Mariner (CBL-Mariner) Security Update for libarchive (11470)
- 904627 Common Base Linux Mariner (CBL-Mariner) Security Update for libarchive (11473-1)
- 904637 Common Base Linux Mariner (CBL-Mariner) Security Update for libarchive (11470-1)
- 904908 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (12316)
- 905079 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (12477)
- 941050 AlmaLinux Security Update for libarchive (ALSA-2023:2532)
- 941070 AlmaLinux Security Update for libarchive (ALSA-2023:3018)