Use-after-free in systemd - CVE-2022-2526

 

Use-after-free in systemd - CVE-2022-2526

Published: August 25, 2022


Vulnerability identifier: #VU66757
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2526
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error within the on_stream_io() and dns_stream_complete() functions in resolved-dns-stream.c, which do not increment the reference counting for the DnsStream object. A remote attacker can send to the system specially crafted DNS responses, trigger a use-after-free error and perform a denial of service (DoS) attack.


Affected software

systemd
redhat-virtualization-host-productimg (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
systemd-devel
systemd-journal-gateway
systemd-libs
libgudev1-devel
systemd-networkd
systemd-python
libgudev1
systemd-resolved
systemd-sysv
systemd (Red Hat package)
systemd (Ubuntu package)
systemd-container
systemd-journal-remote
systemd-pam
systemd-tests
systemd-udev
Submariner
Gatekeeper Operator
IBM Security Verify Bridge
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Oracle Communications Cloud Native Core Automated Test Suite
Netcool Operations Insight
IBM Robotic Process Automation
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
IBM Edge Application Manager
Multicluster Engine for Kubernetes
Red Hat Virtualization
OpenShift Virtualization
Red Hat Virtualization Host
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Anolis OS
CentOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM Security Verify Access
IBM Security Guardium
cflinuxfs3
IBM Cloud Pak for Watson AIOps
XtremIO X2
IBM QRadar Network Packet Capture

How to mitigate CVE-2022-2526

Install updates from vendor's website.

systemd - update to 240
Submariner - update to 0.13.0
Gatekeeper Operator - update to 0.2
OpenShift API for Data Protection (OADP) - update to 1.0.4
IBM Security Verify Bridge - update to 1.0.13.0
IBM MQ Operator - addressed in versions 1.3.8, 2.0.3
Migration Toolkit for Containers - update to 1.7.4
Multicluster Engine for Kubernetes - addressed in versions 2.0.2, 2.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.12, 2.4.6, 2.5.2, 2.6.0
Red Hat OpenShift Container Platform - addressed in versions 3.11.784, 4.6.61, 4.7.59, 4.8.49, 4.9.48, 4.10.31, 4.11.3
redhat-virtualization-host-productimg (Red Hat package) - update to 4.5.2-1.el8
redhat-release-virtualization-host (Red Hat package) - update to 4.5.2-1.el8ev
OpenShift Virtualization - addressed in versions 4.8.7, 4.9.6
OpenShift Logging - addressed in versions 5.3.11, 5.4.5, 5.5.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
IBM Security Verify Access - update to 10.0.5.0
cflinuxfs3 - update to 0.319.0
Netcool Operations Insight - update to 1.6.7
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Cloud Pak for Watson AIOps - update to 3.6.1
Cloud Pak for Data - update to 4.8.5
XtremIO X2 - update to 6.4.1-11
IBM QRadar Network Packet Capture - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Package 3
IBM Robotic Process Automation - update to 21.0.5
systemd - addressed in versions 219-78, 239-58.0.3
systemd-devel - addressed in versions 219-78, 239-58.0.3
systemd-journal-gateway - update to 219-78
systemd-libs - addressed in versions 219-78, 239-58.0.3
libgudev1-devel - update to 219-78
systemd-networkd - update to 219-78
systemd-python - update to 219-78
libgudev1 - update to 219-78
systemd-resolved - update to 219-78
systemd-sysv - update to 219-78
systemd (Red Hat package) - addressed in versions 219-78.el7_9.7, 239-18.el8_1.11, 239-31.el8_2.9, 239-45.el8_4.12, 239-58.el8_6.4
systemd (Ubuntu package) - addressed in versions 237-3ubuntu10.54, 237-3ubuntu10.56
systemd-container - update to 239-58.0.3
systemd-journal-remote - update to 239-58.0.3
systemd-pam - update to 239-58.0.3
systemd-tests - update to 239-58.0.3
systemd-udev - update to 239-58.0.3

External References

Related Security Bulletins