Double Free in ultrajson - CVE-2022-31117
Published: July 5, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when decoding untrusted input. A remote attacker can pass specially crafted data to the application, trigger double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
Fedora
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
Cloud Pak for Security (CP4S)
SUSE Linux Enterprise Module for Packagehub Subpackages
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-ujson-debugsource
python3-ujson
python3-ujson-debuginfo
python2-ujson
python2-ujson-debuginfo
python-ujson-debuginfo
python-ujson (Red Hat package)
dev-python/ujson
python-ujson
Spectrum Discover
Red Hat OpenStack
QRadar Assistant
How to mitigate CVE-2022-31117
Cloud Pak for Security (CP4S) - update to 1.10.7.0
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-ujson-debugsource - update to 1.35-150100.3.5.1
python3-ujson - update to 1.35-150100.3.5.1
python3-ujson-debuginfo - update to 1.35-150100.3.5.1
python2-ujson - update to 1.35-150100.3.5.1
python2-ujson-debuginfo - update to 1.35-150100.3.5.1
python-ujson-debuginfo - update to 1.35-150100.3.5.1
python-ujson (Red Hat package) - update to 2.0.3-3.el8ost
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
QRadar Assistant - update to 3.7.0
dev-python/ujson - update to 5.4.0
python-ujson - addressed in versions 5.4.0-1.el9, 5.4.0-1.fc35, 5.4.0-1.fc36
Red Hat OpenStack - addressed in versions 16.1.9, 16.2.4
External References
Related Security Bulletins
- Multiple vulnerabilities in ultrajson
- SUSE update for python-ujson
- Red Hat OpenStack Platform 16.2 update for python-ujson
- Red Hat OpenStack Platform 16.1 update for python-ujson
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Discover
- Ubuntu update for ujson
- Ubuntu update for ujson
- Ubuntu update for ujson
- Gentoo update for UltraJSON
- Multiple vulnerabilities in IBM QRadar Assistant
- Fedora 36 update for python-ujson
- Fedora EPEL 9 update for python-ujson
- Fedora 35 update for python-ujson