Wind River Support Network

HomeDefectsLIN1022-2504
Fixed

LIN1022-2504 : Security Advisory - systemd - CVE-2022-45873

Created: Nov 24, 2022    Updated: Feb 14, 2023
Resolved Date: Feb 13, 2023
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.

CREATE(Triage):(User=admin) CVE-2022-45873 (https://nvd.nist.gov/vuln/detail/CVE-2022-45873)

CVEs


Live chat
Online