Oval Definition:oval:org.opensuse.security:def:202245873
Revision Date:2023-02-11Version:1
Title:CVE-2022-45873
Description:

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-45873
SUSE CVE-2022-45873
Platform(s):SUSE Linux Enterprise Micro 5.3
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND Package Information
  • libsystemd0 is not affected
  • OR libudev1 is not affected
  • OR systemd is not affected
  • OR systemd-container is not affected
  • OR systemd-journal-remote is not affected
  • OR systemd-sysvinit is not affected
  • OR udev is not affected
  • BACK