yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-32292
Component Overview
Vulnerability Overview
Name
CVE-2022-32292
Source
NVD (
link
)
Debian (
link
)
Description
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.
CWEs
CWE-787
Published Date
Aug 3, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.suse.com/show_bug.cgi?id=1200189
Issue Tracking
https://lore.kernel.org/connman/20220801080043.4861-5-wagi%40monom.org/
Patch
https://security.gentoo.org/glsa/202310-21
Third Party Advisory
https://www.debian.org/security/2022/dsa-5231
Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1200189
Issue Tracking
https://lore.kernel.org/connman/20220801080043.4861-5-wagi%40monom.org/
Patch
https://security.gentoo.org/glsa/202310-21
Third Party Advisory
https://www.debian.org/security/2022/dsa-5231
Third Party Advisory
Analysis
#
Affected Component
Analysis
connman
Patched
Vulnerability Rating
#
9.8
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
connman
buildroot
2025.02.x
1.45
Not Affected
connman
buildroot
master
2.0
Not Affected
connman
yocto
master
2.0
Not Affected
connman
yocto
scarthgap
1.42
Not Affected
Resolved with patches
#
connman (yocto:kirkstone)
#
Title
Author
Resolve
1
gweb: Fix OOB write in received_data()
Nathan Crandall <ncrandall@tesla.com>
CVE-2022-32292