systemd: deadlock in systemd-coredump via a crash with a long backtrace
Published Nov 23, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.27%
Description
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Affected products
No data.
Configuration 1
- ≥ 250 · ≤ 251
- 252
- 252
Configuration 2
- 36
No data.
Red Hat Enterprise Linux 9
systemd-0:250-12.el9_1.3
Fixed · RHSA-2023:0954
Red Hat Enterprise Linux 9
systemd-0:250-12.el9_1.3
Fixed · RHSA-2023:0954
Red Hat Enterprise Linux 7
NetworkManager
Out of support scope
Red Hat Enterprise Linux 7
systemd
Out of support scope
Red Hat Enterprise Linux 8
NetworkManager
Not affected
Red Hat Enterprise Linux 8
systemd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | systemd-0:250-12.el9_1.3 | Fixed | RHSA-2023:0954 |
| Red Hat Enterprise Linux 9 | systemd-0:250-12.el9_1.3 | Fixed | RHSA-2023:0954 |
| Red Hat Enterprise Linux 7 | NetworkManager | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | systemd | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | NetworkManager | Not affected | n/a |
| Red Hat Enterprise Linux 8 | systemd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is only triggered when an application crashes and there is too much data about the crash that needs to be passed to the systemd-coredump utility, specifically more than 65536 bytes, and it will result in a Denial of Service. For this reason, this flaw has been rated as having a moderate security impact. The systemd-coredump utility of systemd as shipped with Red Hat Enterprise Linux 8 does not use the inter-process communication related to this flaw. Therefore, it's not affected.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-45873 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2149063 Issue Tracking
- https://github.com/systemd/systemd/commit/076b807be472630692c5348c60d0c2b7b28ad437 PatchThird Party Advisory
- https://github.com/systemd/systemd/pull/24853#issuecomment-1326561497 Issue TrackingPatchThird Party Advisory
- https://github.com/systemd/systemd/pull/25055#issuecomment-1313733553 Issue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45873
- https://www.cve.org/CVERecord?id=CVE-2022-45873
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-45873 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2149063 | Issue Tracking | |
| https://github.com/systemd/systemd/commit/076b807be472630692c5348c60d0c2b7b28ad437 | PatchThird Party Advisory | |
| https://github.com/systemd/systemd/pull/24853#issuecomment-1326561497 | Issue TrackingPatchThird Party Advisory | |
| https://github.com/systemd/systemd/pull/25055#issuecomment-1313733553 | Issue TrackingPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS5N5SLYAHKENLAJWYBDKU55ICU3SVZF/ | vendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-45873 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-45873 |
Change history (0)
No recorded changes yet.