PT-2022-27663 · Systemd+5 · Systemd+5

Evverx

·

Published

2022-10-18

·

Updated

2025-04-25

·

CVE-2022-45873

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions systemd versions 250 through 251
Description The issue allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in the parse elf object function in shared/elf-util.c. The exploitation methodology involves crashing a binary calling the same function recursively and placing it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Recommendations For versions 250 and 251, as a temporary workaround, consider restricting access to the systemd-coredump.socket file to minimize the risk of exploitation. Additionally, avoid setting MaxConnections to a high value for this socket file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:0954
AZL-11523
AZL-41470
CVE-2022-45873
RHSA-2023:0954
RHSA-2023_0954
RLSA-2023:0954
USN-5928-1

Affected Products

Almalinux
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Systemd