Wind River Support Network

HomeDefectsLIN1022-3606
Fixed

LIN1022-3606 : Security Advisory - samba - CVE-2022-45142

Created: Mar 12, 2023    Updated: Aug 3, 2023
Resolved Date: Jul 16, 2023
Found In Version: 10.22.33.1
Fix Version: 10.22.33.11
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CREATE(Triage):(User=admin) CVE-2022-45142 (https://nvd.nist.gov/vuln/detail/CVE-2022-45142)

CVEs


Live chat
Online