Buffer overflow in sysstat - CVE-2022-39377

 

Buffer overflow in sysstat - CVE-2022-39377

Published: November 10, 2022


Vulnerability identifier: #VU69196
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39377
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the allocate_structures() function in sa_common.c . A remote attacker can trick the victim into running a malicious application on system with a vulnerable version of sysstat, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

sysstat
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
Ubuntu
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
sysstat (Ubuntu package)
isag (Ubuntu package)
sysstat (Red Hat package)
sysstat-doc
sysstat
sysstat-isag
sysstat-debuginfo
sysstat-debugsource
app-admin/sysstat
cflinuxfs3
VMware Tanzu Operations Manager

How to mitigate CVE-2022-39377

Install updates from vendor's website.

sysstat - update to 12.7.1
sysstat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 11.6.1-1ubuntu0.2, 12.2.0-2ubuntu0.2, 12.2.0-2ubuntu0.3, 12.5.2-2ubuntu0.1, 12.5.2-2ubuntu0.2, 12.5.6-1ubuntu0.1, 12.5.6-1ubuntu0.2, 12.6.1-1ubuntu0.1
cflinuxfs3 - update to 0.342.0
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.12
isag (Ubuntu package) - addressed in versions 11.6.1-1ubuntu0.2, 12.2.0-2ubuntu0.2, 12.5.2-2ubuntu0.1, 12.5.6-1ubuntu0.1
sysstat (Red Hat package) - addressed in versions 11.7.3-9.el8, 12.5.4-5.el9
sysstat-doc - addressed in versions 11.7.3-9.0.1, 11.7.3-11.0.1
sysstat - addressed in versions 11.7.3-9.0.1, 11.7.3-11.0.1
sysstat-isag - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debuginfo - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat-debugsource - addressed in versions 12.0.2-20.23.1, 12.0.2-150000.3.37.1
sysstat - addressed in versions 12.2.1-2, 12.2.1-6
sysstat-debuginfo - addressed in versions 12.2.1-2, 12.2.1-6
sysstat-debugsource - addressed in versions 12.2.1-2, 12.2.1-6
sysstat - update to 12.5.6-1
sysstat - addressed in versions 12.5.6-2.fc35, 12.5.6-2.fc36, 12.6.0-4.fc37
app-admin/sysstat - addressed in versions 12.6.2-r1, 12.7.1
sysstat - update to 12.7.1

External References

Related Security Bulletins