OS Command Injection in Emacs - CVE-2022-48338
Published: February 26, 2023
Vulnerability identifier: #VU72574
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-48338
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a malicious gem to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the ruby-find-library-file() function. A malicious Ruby source file can execute arbitrary OS commands on the target system.
Affected software
Emacs
Debian Linux
Gentoo Linux
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Oracle Solaris
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Container Platform
emacs25 (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24 (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24-common (Ubuntu package)
emacs24-el (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs-common (Ubuntu package)
emacs-el (Ubuntu package)
app-editors/emacs
emacs (Debian package)
emacs-nox
emacs
emacs-lucid
emacs-devel
emacs-common
emacs-help
emacs-filesystem
emacs-terminal
emacs-debuginfo
emacs-debugsource
emacs (Red Hat package)
etags-debuginfo
emacs-el
emacs-info
emacs-nox-debuginfo
emacs-x11-debuginfo
etags
emacs-x11
emacs-doc
Red Hat OpenShift Dev Spaces
OpenShift Data Foundation (formerly OpenShift Container Storage)
Debian Linux
Gentoo Linux
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Oracle Solaris
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Container Platform
emacs25 (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24 (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24-common (Ubuntu package)
emacs24-el (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs-common (Ubuntu package)
emacs-el (Ubuntu package)
app-editors/emacs
emacs (Debian package)
emacs-nox
emacs
emacs-lucid
emacs-devel
emacs-common
emacs-help
emacs-filesystem
emacs-terminal
emacs-debuginfo
emacs-debugsource
emacs (Red Hat package)
etags-debuginfo
emacs-el
emacs-info
emacs-nox-debuginfo
emacs-x11-debuginfo
etags
emacs-x11
emacs-doc
Red Hat OpenShift Dev Spaces
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2022-48338
Install updates from vendor's website.
Red Hat OpenShift Container Platform - update to 4.13.2
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-common (Ubuntu package) - update to Ubuntu Pro
emacs24-el (Ubuntu package) - update to Ubuntu Pro
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
Red Hat OpenShift Dev Spaces - update to 3.15.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
app-editors/emacs - update to 9.6.23
emacs (Debian package) - update to 1:27.1+1-3.1+deb11u2
emacs-nox - update to 27.1-10
emacs - update to 27.1-10
emacs-lucid - update to 27.1-10
emacs-devel - update to 27.1-10
emacs-common - update to 27.1-10
emacs-help - update to 27.1-10
emacs-filesystem - update to 27.1-10
emacs-terminal - update to 27.1-10
emacs-debuginfo - update to 27.1-10
emacs-debugsource - update to 27.1-10
emacs (Red Hat package) - update to 27.2-8.el9_2.1
emacs - addressed in versions 27.2-8.0.2, 29.1-1
emacs-common - addressed in versions 27.2-8.0.2, 29.1-1
emacs-lucid - addressed in versions 27.2-8.0.2, 29.1-1
emacs-nox - addressed in versions 27.2-8.0.2, 29.1-1
emacs-filesystem - addressed in versions 27.2-8.0.2, 29.1-1
emacs-terminal - addressed in versions 27.2-8.0.2, 29.1-1
etags-debuginfo - update to 27.2-150400.3.6.1
emacs-debugsource - update to 27.2-150400.3.6.1
emacs-el - update to 27.2-150400.3.6.1
emacs-info - update to 27.2-150400.3.6.1
emacs - update to 27.2-150400.3.6.1
emacs-debuginfo - update to 27.2-150400.3.6.1
emacs-nox - update to 27.2-150400.3.6.1
emacs-nox-debuginfo - update to 27.2-150400.3.6.1
emacs-x11-debuginfo - update to 27.2-150400.3.6.1
etags - update to 27.2-150400.3.6.1
emacs-x11 - update to 27.2-150400.3.6.1
emacs - update to 28.2-3
emacs - addressed in versions 28.3-0.rc1.fc37, 28.3-0.rc1.fc38
emacs-devel - update to 29.1-1
emacs-doc - update to 29.1-1
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-common (Ubuntu package) - update to Ubuntu Pro
emacs24-el (Ubuntu package) - update to Ubuntu Pro
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
Red Hat OpenShift Dev Spaces - update to 3.15.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
app-editors/emacs - update to 9.6.23
emacs (Debian package) - update to 1:27.1+1-3.1+deb11u2
emacs-nox - update to 27.1-10
emacs - update to 27.1-10
emacs-lucid - update to 27.1-10
emacs-devel - update to 27.1-10
emacs-common - update to 27.1-10
emacs-help - update to 27.1-10
emacs-filesystem - update to 27.1-10
emacs-terminal - update to 27.1-10
emacs-debuginfo - update to 27.1-10
emacs-debugsource - update to 27.1-10
emacs (Red Hat package) - update to 27.2-8.el9_2.1
emacs - addressed in versions 27.2-8.0.2, 29.1-1
emacs-common - addressed in versions 27.2-8.0.2, 29.1-1
emacs-lucid - addressed in versions 27.2-8.0.2, 29.1-1
emacs-nox - addressed in versions 27.2-8.0.2, 29.1-1
emacs-filesystem - addressed in versions 27.2-8.0.2, 29.1-1
emacs-terminal - addressed in versions 27.2-8.0.2, 29.1-1
etags-debuginfo - update to 27.2-150400.3.6.1
emacs-debugsource - update to 27.2-150400.3.6.1
emacs-el - update to 27.2-150400.3.6.1
emacs-info - update to 27.2-150400.3.6.1
emacs - update to 27.2-150400.3.6.1
emacs-debuginfo - update to 27.2-150400.3.6.1
emacs-nox - update to 27.2-150400.3.6.1
emacs-nox-debuginfo - update to 27.2-150400.3.6.1
emacs-x11-debuginfo - update to 27.2-150400.3.6.1
etags - update to 27.2-150400.3.6.1
emacs-x11 - update to 27.2-150400.3.6.1
emacs - update to 28.2-3
emacs - addressed in versions 28.3-0.rc1.fc37, 28.3-0.rc1.fc38
emacs-devel - update to 29.1-1
emacs-doc - update to 29.1-1
External References
Related Security Bulletins
- OS command injection in GNU Emacs
- Debian update for emacs
- SUSE update for emacs
- Red Hat Enterprise Linux 9 update for emacs
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Solaris third-party software
- Fedora 38 update for emacs
- Fedora 37 update for emacs
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- openEuler update for emacs
- Gentoo update for GNU Emacs, Org Mode
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Amazon Linux AMI update for emacs
- Ubuntu update for emacs
- Anolis OS update for emacs
- Anolis OS update for emacs