CVE-2022-45873
Summary
| CVE | CVE-2022-45873 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-23 23:15:00 UTC |
| Updated | 2023-11-07 03:54:00 UTC |
| Description | systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Fix coredump deadlock with overly long backtraces by keszybz · Pull Request #25055 · systemd/systemd · GitHub |
MISC |
github.com |
|
| resolved: various monitor fixes by poettering · Pull Request #24853 · systemd/systemd · GitHub |
MISC |
github.com |
|
| coredump: avoid deadlock when passing processed backtrace data · systemd/systemd@076b807 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: systemd-250.9-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: systemd-250.9-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160491 Oracle Enterprise Linux Security Update for systemd (ELSA-2023-0954)
- 184939 Debian Security Update for systemd (CVE-2022-45873)
- 199221 Ubuntu Security Notification for systemd Vulnerabilities (USN-5928-1)
- 241228 Red Hat Update for systemd (RHSA-2023:0954)
- 283572 Fedora Security Update for systemd (FEDORA-2022-ef4f57b072)
- 355284 Amazon Linux Security Advisory for systemd : ALAS2023-2023-025
- 904614 Common Base Linux Mariner (CBL-Mariner) Security Update for systemd (11523)
- 904778 Common Base Linux Mariner (CBL-Mariner) Security Update for systemd (11523-1)
- 940944 AlmaLinux Security Update for systemd (ALSA-2023:0954)
- 960907 Rocky Linux Security Update for systemd (RLSA-2023:0954)