Memory leak in sdl2 - CVE-2022-4743
Published: January 11, 2023
Vulnerability identifier: #VU71094
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4743
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak within the GLES_CreateTexture() function in render/opengles/SDL_render_gles.c. A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
sdl2
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Oracle Solaris
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
SUSE Linux Enterprise Module for Packagehub Subpackages
SDL2-debugsource
libSDL2-2_0-0
libSDL2-2_0-0-debuginfo
libSDL2-devel
libSDL2-2_0-0-32bit
libSDL2-2_0-0-32bit-debuginfo
libSDL2-devel-32bit
SDL2
SDL2-devel
SDL2-debuginfo
media-libs/libsdl2
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Oracle Solaris
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
SUSE Linux Enterprise Module for Packagehub Subpackages
SDL2-debugsource
libSDL2-2_0-0
libSDL2-2_0-0-debuginfo
libSDL2-devel
libSDL2-2_0-0-32bit
libSDL2-2_0-0-32bit-debuginfo
libSDL2-devel-32bit
SDL2
SDL2-devel
SDL2-debuginfo
media-libs/libsdl2
How to mitigate CVE-2022-4743
Install updates from vendor's website.
sdl2 - update to 2.26.0
SDL2-debugsource - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0 - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-debuginfo - update to 2.0.8-150200.11.9.1
libSDL2-devel - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-32bit - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-32bit-debuginfo - update to 2.0.8-150200.11.9.1
libSDL2-devel-32bit - update to 2.0.8-150200.11.9.1
SDL2 - update to 2.0.12-2
SDL2-devel - update to 2.0.12-2
SDL2-debuginfo - update to 2.0.12-2
SDL2-debugsource - update to 2.0.12-2
media-libs/libsdl2 - update to 2.26.0
SDL2-debugsource - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0 - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-debuginfo - update to 2.0.8-150200.11.9.1
libSDL2-devel - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-32bit - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-32bit-debuginfo - update to 2.0.8-150200.11.9.1
libSDL2-devel-32bit - update to 2.0.8-150200.11.9.1
SDL2 - update to 2.0.12-2
SDL2-devel - update to 2.0.12-2
SDL2-debuginfo - update to 2.0.12-2
SDL2-debugsource - update to 2.0.12-2
media-libs/libsdl2 - update to 2.26.0