Out-of-bounds write in Pixman - CVE-2022-44638
Published: November 9, 2022
Vulnerability identifier: #VU69176
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-44638
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within the rasterize_edges_8() function. A remote attacker can trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
Pixman
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
Migration Toolkit for Runtimes
OpenShift Logging
Red Hat OpenShift Dev Spaces
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Virtualization
IBM Watson Machine Learning Accelerator
cflinuxfs3
PowerStore T
EMC Cloud Tiering Appliance
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
libpixman-1-dev (Ubuntu package)
libpixman-1-0 (Ubuntu package)
libpixman-1-0
libpixman-1-0-32bit
libpixman-1-0-debuginfo
libpixman-1-0-debuginfo-32bit
pixman-debugsource
libpixman-1-0-devel
libpixman-1-0-32bit-debuginfo
pixman (Red Hat package)
pixman (Debian package)
pixman
pixman-debuginfo
pixman-devel
x11-libs/pixman
mingw-pixman
mingw-pixman (Red Hat package)
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
Migration Toolkit for Runtimes
OpenShift Logging
Red Hat OpenShift Dev Spaces
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Virtualization
IBM Watson Machine Learning Accelerator
cflinuxfs3
PowerStore T
EMC Cloud Tiering Appliance
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
libpixman-1-dev (Ubuntu package)
libpixman-1-0 (Ubuntu package)
libpixman-1-0
libpixman-1-0-32bit
libpixman-1-0-debuginfo
libpixman-1-0-debuginfo-32bit
pixman-debugsource
libpixman-1-0-devel
libpixman-1-0-32bit-debuginfo
pixman (Red Hat package)
pixman (Debian package)
pixman
pixman-debuginfo
pixman-devel
x11-libs/pixman
mingw-pixman
mingw-pixman (Red Hat package)
How to mitigate CVE-2022-44638
Install updates from vendor's website.
Pixman - update to 0.42.2
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift Container Platform - addressed in versions 4.11.54, 4.12.45, 4.13.24, 4.14.4, 4.16.15, 4.17.0
OpenShift Virtualization - update to 4.12.9
IBM Watson Machine Learning Accelerator - update to 5.0.3
OpenShift Logging - update to 5.8.2
libpixman-1-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libpixman-1-0 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 0.34.0-2ubuntu0.1, 0.38.4-0ubuntu2.1, 0.40.0-1ubuntu0.22.04.1, 0.40.0-1ubuntu0.22.10.1
libpixman-1-0 - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-32bit - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-debuginfo - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-debuginfo-32bit - update to 0.34.0-8.3.1
pixman-debugsource - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-devel - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-32bit-debuginfo - addressed in versions 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
pixman (Red Hat package) - addressed in versions 0.38.4-3.el8_6, 0.38.4-3.el8_8, 0.40.0-6.el9_0, 0.40.0-6.el9_2, 0.40.0-6.el9_3
pixman (Debian package) - update to 0.40.0-1.1~deb11u1
pixman - update to 0.40.0-2
pixman-debugsource - update to 0.40.0-2
pixman-debuginfo - update to 0.40.0-2
pixman-devel - update to 0.40.0-2
pixman - update to 0.40.0-6
pixman-devel - update to 0.40.0-6
x11-libs/pixman - update to 0.42.2
mingw-pixman - addressed in versions 0.42.2-1.fc35, 0.42.2-1.fc36, 0.42.2-1.fc37
mingw-pixman (Red Hat package) - update to 0.42.2-3.el9
cflinuxfs3 - update to 0.333.0
PowerStore T - update to 3.5.0.1-2083289
Red Hat OpenShift Dev Spaces - update to 3.16.0
Red Hat Migration Toolkit for Applications - update to 6.2
IBM Security Verify Governance - update to 10.0.2.0.4
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift Container Platform - addressed in versions 4.11.54, 4.12.45, 4.13.24, 4.14.4, 4.16.15, 4.17.0
OpenShift Virtualization - update to 4.12.9
IBM Watson Machine Learning Accelerator - update to 5.0.3
OpenShift Logging - update to 5.8.2
libpixman-1-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libpixman-1-0 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 0.34.0-2ubuntu0.1, 0.38.4-0ubuntu2.1, 0.40.0-1ubuntu0.22.04.1, 0.40.0-1ubuntu0.22.10.1
libpixman-1-0 - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-32bit - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-debuginfo - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-debuginfo-32bit - update to 0.34.0-8.3.1
pixman-debugsource - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-devel - addressed in versions 0.34.0-8.3.1, 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
libpixman-1-0-32bit-debuginfo - addressed in versions 0.34.0-150000.7.5.1, 0.40.0-150400.3.3.1
pixman (Red Hat package) - addressed in versions 0.38.4-3.el8_6, 0.38.4-3.el8_8, 0.40.0-6.el9_0, 0.40.0-6.el9_2, 0.40.0-6.el9_3
pixman (Debian package) - update to 0.40.0-1.1~deb11u1
pixman - update to 0.40.0-2
pixman-debugsource - update to 0.40.0-2
pixman-debuginfo - update to 0.40.0-2
pixman-devel - update to 0.40.0-2
pixman - update to 0.40.0-6
pixman-devel - update to 0.40.0-6
x11-libs/pixman - update to 0.42.2
mingw-pixman - addressed in versions 0.42.2-1.fc35, 0.42.2-1.fc36, 0.42.2-1.fc37
mingw-pixman (Red Hat package) - update to 0.42.2-3.el9
cflinuxfs3 - update to 0.333.0
PowerStore T - update to 3.5.0.1-2083289
Red Hat OpenShift Dev Spaces - update to 3.16.0
Red Hat Migration Toolkit for Applications - update to 6.2
IBM Security Verify Governance - update to 10.0.2.0.4
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
External References
Related Security Bulletins
- Remote code execution in Pixman
- Ubuntu update for pixman
- Debian update for pixman
- Cloud Foundry Foundation cflinuxfs3 update for pixman
- SUSE update for pixman
- SUSE update for pixman
- SUSE update for pixman
- Ubuntu update for pixman
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell PowerStore Family
- Red Hat Enterprise Linux 9.2 Extended Update Support update for pixman
- Red Hat Enterprise Linux 9.0 Extended Update Support update for pixman
- Red Hat Enterprise Linux 8.6 Extended Update Support update for pixman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 8.8 Extended Update Support update for pixman
- Red Hat Enterprise Linux 9 update for pixman
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- openEuler update for pixman
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Red Hat Enterprise Linux 9 update for mingw-pixman
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Gentoo update for Pixman
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Fedora 35 update for mingw-pixman
- Fedora 36 update for mingw-pixman
- Fedora 37 update for mingw-pixman
- Anolis OS update for pixman
- Anolis OS update for pixman
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data