Resource exhaustion in systemd - CVE-2022-45873
Published: March 6, 2023
Vulnerability identifier: #VU72887
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45873
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a deadlock within the parse_elf_object() function in shared/elf-util.c. A local user can perform a denial of service (DoS) attack.
Affected software
systemd
systemd (Ubuntu package)
systemd (Red Hat package)
sys-apps/systemd
Isolation Segment
VMware Tanzu Application Service for VMs
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Fedora
cflinuxfs3
Platform Automation Toolkit
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
HPE Moonshot 1500 Chassis Manager
systemd (Ubuntu package)
systemd (Red Hat package)
sys-apps/systemd
Isolation Segment
VMware Tanzu Application Service for VMs
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Fedora
cflinuxfs3
Platform Automation Toolkit
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
HPE Moonshot 1500 Chassis Manager
How to mitigate CVE-2022-45873
Install updates from vendor's website.
systemd - addressed in versions 250.9, 251.9
systemd (Ubuntu package) - addressed in versions Ubuntu Pro, 237-3ubuntu10.57, 245.4-4ubuntu3.20, 249.11-0ubuntu3.7, 251.4-1ubuntu7.1
cflinuxfs3 - update to 0.357.0
VMware Tanzu Operations Manager - addressed in versions 2.10.55, 3.0.6
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
systemd - update to 250.9-1.fc36
systemd (Red Hat package) - update to 250-12.el9_1.3
sys-apps/systemd - update to 252.4
systemd - update to 252.4-1161
systemd (Ubuntu package) - addressed in versions Ubuntu Pro, 237-3ubuntu10.57, 245.4-4ubuntu3.20, 249.11-0ubuntu3.7, 251.4-1ubuntu7.1
cflinuxfs3 - update to 0.357.0
VMware Tanzu Operations Manager - addressed in versions 2.10.55, 3.0.6
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
systemd - update to 250.9-1.fc36
systemd (Red Hat package) - update to 250-12.el9_1.3
sys-apps/systemd - update to 252.4
systemd - update to 252.4-1161
External References
- https://github.com/systemd/systemd/commit/076b807be472630692c5348c60d0c2b7b28ad437
- https://github.com/systemd/systemd/pull/25055#issuecomment-1313733553
- https://github.com/systemd/systemd/pull/24853#issuecomment-1326561497
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/
Related Security Bulletins
- Denial of service in systemd
- Red Hat Enterprise Linux 9 update for systemd
- Ubuntu update for systemd
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for systemd
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Gentoo update for systemd
- Amazon Linux AMI update for systemd
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Fedora 36 update for systemd