HomeDefectsLIN10-10724
Not to be fixed

LIN10-10724 : Security Advisory - python - CVE-2022-37454

Created: Oct 21, 2022    Updated: Dec 22, 2022
Resolved Date: Dec 22, 2022
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

https://github.com/python/cpython/issues/98517

CREATE(Triage):(User=admin) CVE-2022-37454 (https://nvd.nist.gov/vuln/detail/CVE-2022-37454)