Resource exhaustion in systemd - CVE-2022-45873

 

Resource exhaustion in systemd - CVE-2022-45873

Published: March 6, 2023


Vulnerability identifier: #VU72887
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45873
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a deadlock within the parse_elf_object() function in shared/elf-util.c. A local user can perform a denial of service (DoS) attack.


Affected software

systemd
systemd (Ubuntu package)
systemd (Red Hat package)
sys-apps/systemd
Isolation Segment
VMware Tanzu Application Service for VMs
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Fedora
cflinuxfs3
Platform Automation Toolkit
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
HPE Moonshot 1500 Chassis Manager

How to mitigate CVE-2022-45873

Install updates from vendor's website.

systemd - addressed in versions 250.9, 251.9
systemd (Ubuntu package) - addressed in versions Ubuntu Pro, 237-3ubuntu10.57, 245.4-4ubuntu3.20, 249.11-0ubuntu3.7, 251.4-1ubuntu7.1
cflinuxfs3 - update to 0.357.0
VMware Tanzu Operations Manager - addressed in versions 2.10.55, 3.0.6
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
systemd - update to 250.9-1.fc36
systemd (Red Hat package) - update to 250-12.el9_1.3
sys-apps/systemd - update to 252.4
systemd - update to 252.4-1161

External References

Related Security Bulletins