Stack-based buffer overflow in LibSass - CVE-2022-26592

 

Stack-based buffer overflow in LibSass - CVE-2022-26592

Published: December 22, 2023 / Updated: March 12, 2024


Vulnerability identifier: #VU84724
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26592
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the CompoundSelector::has_real_parent_ref() function. A remote attacker can pass specially crafted input to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

LibSass
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Package Hub 15
openSUSE Leap
openEuler
libsass-debuginfo
libsass-devel
libsass-debugsource
libsass
libsass-3_6_5-1-debuginfo
libsass-3_6_5-1

How to mitigate CVE-2022-26592

Install updates from vendor's website.

LibSass - update to 3.6.6
openEuler - addressed in versions 20.03 LTS SP1, 20.03 LTS SP3, 20.03 LTS SP4, 22.03 LTS, 22.03 LTS SP1, 22.03 LTS SP2
libsass-debuginfo - update to 3.6.4-2
libsass-devel - update to 3.6.4-2
libsass-debugsource - update to 3.6.4-2
libsass - update to 3.6.4-2
libsass-3_6_5-1-debuginfo - update to 3.6.5-150200.4.10.1
libsass-3_6_5-1 - update to 3.6.5-150200.4.10.1
libsass-devel - update to 3.6.5-150200.4.10.1
libsass-debugsource - update to 3.6.5-150200.4.10.1

External References

Related Security Bulletins