Heap-based buffer overflow in Bash - CVE-2022-3715
Published: January 23, 2023 / Updated: May 23, 2025
Vulnerability identifier: #VU71454
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3715
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in valid_parameter_transform() function in GNU bash. A local user can trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
Bash
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
NetObserv Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Dell EMC Container Storage Modules
LANTIME Operating System Firmware (LTOS)
PowerScale OneFS
Watson Studio on Cloud Pak for Data
bash (Ubuntu package)
bash-debuginfo
bash-help
bash-devel
bash-debugsource
bash
bash (Red Hat package)
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
NetObserv Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Dell EMC Container Storage Modules
LANTIME Operating System Firmware (LTOS)
PowerScale OneFS
Watson Studio on Cloud Pak for Data
bash (Ubuntu package)
bash-debuginfo
bash-help
bash-devel
bash-debugsource
bash
bash (Red Hat package)
How to mitigate CVE-2022-3715
Install updates from vendor's website.
Bash - update to 5.2
NetObserv Operator - update to 1.1.0
OpenShift sandboxed containers - update to 1.4.1
Red Hat OpenShift Container Platform - update to 4.13.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
Dell EMC Container Storage Modules - update to 1.7.0
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Watson Studio on Cloud Pak for Data - update to 5.0.3
bash (Ubuntu package) - update to 5.1-6ubuntu1.1
bash-debuginfo - update to 5.1.8-6
bash-help - update to 5.1.8-6
bash-devel - update to 5.1.8-6
bash-debugsource - update to 5.1.8-6
bash - update to 5.1.8-6
bash (Red Hat package) - update to 5.1.8-6.el9_1
bash - update to 5.2.15-1
PowerScale OneFS - update to 9.5.0.2
NetObserv Operator - update to 1.1.0
OpenShift sandboxed containers - update to 1.4.1
Red Hat OpenShift Container Platform - update to 4.13.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
Dell EMC Container Storage Modules - update to 1.7.0
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Watson Studio on Cloud Pak for Data - update to 5.0.3
bash (Ubuntu package) - update to 5.1-6ubuntu1.1
bash-debuginfo - update to 5.1.8-6
bash-help - update to 5.1.8-6
bash-devel - update to 5.1.8-6
bash-debugsource - update to 5.1.8-6
bash - update to 5.1.8-6
bash (Red Hat package) - update to 5.1.8-6.el9_1
bash - update to 5.2.15-1
PowerScale OneFS - update to 9.5.0.2
External References
Related Security Bulletins
- Privilege escalation in GNU Bash
- Red Hat Enterprise Linux 9 update for bash
- Multiple vulnerabilities in NetObserv Operator
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in Dell Container Storage Modules
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- openEuler 22.03 LTS update for bash
- Ubuntu update for bash
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for bash
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop
- Meinberg LANTIME firmware update for third-party components (January 2024)