yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-31212
Component Overview
Vulnerability Overview
Name
CVE-2022-31212
Source
NVD (
link
)
Debian (
link
)
Description
An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied.
CWEs
CWE-125
Published Date
Jul 17, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/bus1/dbus-broker/compare/v30...v31
Patch
https://sec-consult.com/vulnerability-lab/advisory/memory-corruption-vulnerabilities-dbus-broker/
Exploit
https://github.com/bus1/dbus-broker/compare/v30...v31
Patch
https://sec-consult.com/vulnerability-lab/advisory/memory-corruption-vulnerabilities-dbus-broker/
Exploit
Analysis
#
Affected Component
Analysis
dbus-broker
Patched
Vulnerability Rating
#
7.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
dbus-broker
buildroot
2025.02.x
36
Not Affected
dbus-broker
buildroot
master
37
Not Affected
dbus-broker
yocto
master
37
Not Affected
dbus-broker
yocto
scarthgap
32
Not Affected
Resolved with patches
#
dbus-broker (yocto:kirkstone)
#
Title
Author
Resolve
1
strnspn: fix buffer overflow
David Rheinsberg <david.rheinsberg@gmail.com>
CVE-2022-31212