Out-of-bounds read in Cap'n Proto and capnproto-rust - CVE-2022-46149

 

Out-of-bounds read in Cap'n Proto and capnproto-rust - CVE-2022-46149

Published: December 29, 2022


Vulnerability identifier: #VU70537
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46149
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the list-of-list logic. A remote attacker can pass specially crafted data to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

Cap'n Proto
capnproto-rust
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Red Hat OpenShift Container Platform
conmon-rs (Red Hat package)
capnproto
capnproto-debuginfo
capnproto-debugsource
libcapnp-0_9
libcapnp-0_9-debuginfo
libcapnp-devel
rust-capnp
fastnetmon
rust-sequoia-octopus-librnp
librime
NetworkManager (Red Hat package)
sonic-visualiser
openshift4-aws-iso (Red Hat package)
openshift-ansible (Red Hat package)
rr

How to mitigate CVE-2022-46149

Install updates from vendor's website.

Cap'n Proto - addressed in versions 0.7.1, 0.8.1, 0.9.2, 0.10.3
capnproto-rust - addressed in versions 0.13.7, 0.14.11, 0.15.2
Red Hat OpenShift Container Platform - update to 4.12.9
conmon-rs (Red Hat package) - addressed in versions 0.5.1-3.rhaos4.12.git.el8, 0.5.1-3.rhaos4.12.git.el9
capnproto - addressed in versions 0.7.1-1.el8, 0.9.2-1.fc36, 0.9.2-1.fc37, 0.10.3-1.el9, 0.10.3-1.fc38
capnproto-debuginfo - update to 0.9.1-150400.3.4.1
capnproto-debugsource - update to 0.9.1-150400.3.4.1
libcapnp-0_9 - update to 0.9.1-150400.3.4.1
libcapnp-0_9-debuginfo - update to 0.9.1-150400.3.4.1
libcapnp-devel - update to 0.9.1-150400.3.4.1
capnproto - update to 0.9.1-150400.3.4.1
rust-capnp - addressed in versions 0.14.11-1.fc36, 0.14.11-1.fc37, 0.14.11-1.fc38
fastnetmon - addressed in versions 1.2.1-2.20220528git420e7b8.fc36, 1.2.1-4.20220528git420e7b8.fc37, 1.2.1-5.20220528git420e7b8.fc38
rust-sequoia-octopus-librnp - addressed in versions 1.4.1-2.fc36, 1.4.1-2.fc37, 1.4.1-2.fc38
librime - addressed in versions 1.7.3-2.fc36, 1.7.3-3.fc37, 1.7.3-5.fc38
NetworkManager (Red Hat package) - update to 1.36.0-13.el8_6
sonic-visualiser - addressed in versions 4.5-2.fc36, 4.5-3.fc37, 4.5-4.fc38
openshift4-aws-iso (Red Hat package) - update to 4.12.0-202303211342.p0.ge6f12ae.assembly.stream.el8
openshift-ansible (Red Hat package) - update to 4.12.0-202303211955.p0.gab53575.assembly.stream.el8
rr - addressed in versions 5.6.0-2.el8, 5.6.0-2.fc36, 5.6.0-2.fc37, 5.6.0-3.fc38

External References

Related Security Bulletins