Integer overflow in protobuf-c - CVE-2022-48468
Published: April 25, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within parse_required_member() function. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Netezza Appliance
Storage Defender - Resiliency Service
Business Automation Insights
PowerStore T
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
IBM QRadar Incident Forensics
IBM Sterling Order Management
Robotic Process Automation for Cloud Pak
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Anolis OS
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Service Telemetry Framework
OpenShift Pipelines
Red Hat Advanced Cluster Security for Kubernetes
IBM Cloud Pak for Business Automation
Submariner
Netcool Operations Insight
Red Hat OpenShift Dev Spaces
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Workload Scheduler
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Virtualization
OpenShift Service Mesh
Multicluster Engine for Kubernetes
IBM Qradar SIEM
Red Hat Single Sign-On
protobuf-c-devel
protobuf-c-compiler
protobuf-c
protobuf-c (Red Hat package)
libprotobuf-c1
protobuf-c-debuginfo
protobuf-c-debugsource
libprotobuf-c-devel
libprotobuf-c1-debuginfo
dev-libs/protobuf-c
libsignal-protocol-c
Red Hat OpenShift GitOps
How to mitigate CVE-2022-48468
Netezza Appliance - update to 1.0.0.1
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3, 1.8.4
OpenShift Pipelines - update to 1.10.6
Storage Defender - Resiliency Service - update to 2.0.11
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.8, 4.1.6, 4.3.1
OpenShift Virtualization - addressed in versions 4.12.9, 4.13.6, 4.14.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
Red Hat Single Sign-On - update to 7.6.6
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Submariner - update to 0.18.5
protobuf-c-devel - update to 1.3.0-7
protobuf-c-compiler - update to 1.3.0-7
protobuf-c - update to 1.3.0-7
protobuf-c (Red Hat package) - addressed in versions 1.3.0-8.el8, 1.3.0-8.el8_8, 1.3.3-13.el9
libprotobuf-c1 - addressed in versions 1.3.0-150000.3.3.1, 1.3.2-150200.3.3.1
protobuf-c-debuginfo - addressed in versions 1.3.0-150000.3.3.1, 1.3.2-150200.3.3.1
protobuf-c-debugsource - addressed in versions 1.3.0-150000.3.3.1, 1.3.2-150200.3.3.1
libprotobuf-c-devel - addressed in versions 1.3.0-150000.3.3.1, 1.3.2-150200.3.3.1
libprotobuf-c1-debuginfo - addressed in versions 1.3.0-150000.3.3.1, 1.3.2-150200.3.3.1
protobuf-c-debuginfo - update to 1.3.2-5
protobuf-c-debugsource - update to 1.3.2-5
protobuf-c-devel - update to 1.3.2-5
protobuf-c - update to 1.3.2-5
protobuf-c - update to 1.3.2-150200.3.3.1
dev-libs/protobuf-c - update to 1.4.1
Netcool Operations Insight - update to 1.6.12
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
libsignal-protocol-c - addressed in versions 2.3.3-7.fc36, 2.3.3-8.el8, 2.3.3-8.el9, 2.3.3-8.fc37, 2.3.3-9.fc38
OpenShift Service Mesh - update to 2.5.2
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.7.4
PowerStore T - update to 3.6.1.2-2315284
Red Hat OpenShift Dev Spaces - update to 3.16.0
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.16.44, 4.17.0
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Sterling Order Management - update to 10.0.2403.1
IBM Workload Scheduler - addressed in versions 10.1.0.4, 10.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.13, 23.0.13
External References
Related Security Bulletins
- Denial of service in Protobuf-c
- SUSE update for protobuf-c
- SUSE update for protobuf-c
- Fedora 38 update for libsignal-protocol-c
- Fedora EPEL 9 update for libsignal-protocol-c
- Fedora EPEL 8 update for libsignal-protocol-c
- Fedora 37 update for libsignal-protocol-c
- Fedora 36 update for libsignal-protocol-c
- Red Hat Enterprise Linux 9 update for protobuf-c
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for protobuf-c
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.10
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.74
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.1
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Integer overflow in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Workload Scheduler
- openEuler 20.03 LTS SP1 update for protobuf-c
- openEuler 20.03 LTS SP3 update for protobuf-c
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Red Hat Enterprise Linux 8 update for protobuf-c
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Dell PowerStoreT OS
- Gentoo update for protobuf-c
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Anolis OS update for protobuf-c
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Submariner 0.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM Netezza Appliance update for protobuf-c