Buffer overflow in sysstat - CVE-2022-39377
Published: November 10, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the allocate_structures() function in sa_common.c . A remote attacker can trick the victim into running a malicious application on system with a vulnerable version of sysstat, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
Ubuntu
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
sysstat (Ubuntu package)
isag (Ubuntu package)
sysstat (Red Hat package)
sysstat-doc
sysstat
sysstat-isag
sysstat-debuginfo
sysstat-debugsource
app-admin/sysstat
cflinuxfs3
VMware Tanzu Operations Manager
How to mitigate CVE-2022-39377
sysstat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 11.6.1-1ubuntu0.2, 12.2.0-2ubuntu0.2, 12.2.0-2ubuntu0.3, 12.5.2-2ubuntu0.1, 12.5.2-2ubuntu0.2, 12.5.6-1ubuntu0.1, 12.5.6-1ubuntu0.2, 12.6.1-1ubuntu0.1
cflinuxfs3 - update to 0.342.0
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.12
isag (Ubuntu package) - addressed in versions 11.6.1-1ubuntu0.2, 12.2.0-2ubuntu0.2, 12.5.2-2ubuntu0.1, 12.5.6-1ubuntu0.1
sysstat (Red Hat package) - addressed in versions 11.7.3-9.el8, 12.5.4-5.el9
sysstat-doc - addressed in versions 11.7.3-9.0.1, 11.7.3-11.0.1
sysstat - addressed in versions 11.7.3-9.0.1, 11.7.3-11.0.1
sysstat-isag - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debuginfo - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debugsource - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat - addressed in versions 12.2.1-2, 12.2.1-6
sysstat-debuginfo - addressed in versions 12.2.1-2, 12.2.1-6
sysstat-debugsource - addressed in versions 12.2.1-2, 12.2.1-6
sysstat - update to 12.5.6-1
sysstat - addressed in versions 12.5.6-2.fc35, 12.5.6-2.fc36, 12.6.0-4.fc37
app-admin/sysstat - addressed in versions 12.6.2-r1, 12.7.1
sysstat - update to 12.7.1
External References
Related Security Bulletins
- Buffer overflow in sysstat
- Slackware Linux update for sysstat
- Gentoo update for sysstat
- Ubuntu update for sysstat
- Ubuntu update for sysstat
- Cloud Foundry Foundation cflinuxfs3 update for Sysstat
- Red Hat Enterprise Linux 9 update for sysstat
- Red Hat Enterprise Linux 8 update for sysstat
- Multiple vulnerabilities in Oracle Linux
- Ubuntu update for sysstat
- VMware Tanzu products update for Sysstat
- openEuler update for sysstat
- openEuler update for sysstat
- Amazon Linux AMI update for sysstat
- Fedora 35 update for sysstat
- Fedora 36 update for sysstat
- Fedora 37 update for sysstat
- SUSE update for sysstat
- SUSE update for sysstat
- Amazon Linux AMI update for sysstat
- Anolis OS update for sysstat
- Anolis OS update for sysstat
- Gentoo update for sysstat