Memory leak in sdl2 - CVE-2022-4743

 

Memory leak in sdl2 - CVE-2022-4743

Published: January 11, 2023


Vulnerability identifier: #VU71094
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4743
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak within the GLES_CreateTexture() function in render/opengles/SDL_render_gles.c. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

sdl2
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Oracle Solaris
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
SUSE Linux Enterprise Module for Packagehub Subpackages
SDL2-debugsource
libSDL2-2_0-0
libSDL2-2_0-0-debuginfo
libSDL2-devel
libSDL2-2_0-0-32bit
libSDL2-2_0-0-32bit-debuginfo
libSDL2-devel-32bit
SDL2
SDL2-devel
SDL2-debuginfo
media-libs/libsdl2

How to mitigate CVE-2022-4743

Install updates from vendor's website.

sdl2 - update to 2.26.0
SDL2-debugsource - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0 - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-debuginfo - update to 2.0.8-150200.11.9.1
libSDL2-devel - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-32bit - update to 2.0.8-150200.11.9.1
libSDL2-2_0-0-32bit-debuginfo - update to 2.0.8-150200.11.9.1
libSDL2-devel-32bit - update to 2.0.8-150200.11.9.1
SDL2 - update to 2.0.12-2
SDL2-devel - update to 2.0.12-2
SDL2-debuginfo - update to 2.0.12-2
SDL2-debugsource - update to 2.0.12-2
media-libs/libsdl2 - update to 2.26.0

External References

Related Security Bulletins