Wind River Support Network

HomeDefectsLIN1021-5419
Fixed

LIN1021-5419 : Security Advisory - samba - CVE-2022-45142

Created: Mar 12, 2023    Updated: Mar 22, 2023
Resolved Date: Mar 22, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.17
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CREATE(Triage):(User=admin) CVE-2022-45142 (https://nvd.nist.gov/vuln/detail/CVE-2022-45142)

CVEs


Live chat
Online