Logo
vulnerabilityCVE-2022-45873
Name
CVE-2022-45873
Source
NVD ( link)Debian ( link)
Description
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
systemd
Exploitable

Vulnerability Ratings#


5.5
CVSSv31
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
256.17
Not Affected
buildroot
master
258.7
Not Affected
yocto
master
259.5
Not Affected
yocto
scarthgap
255.21
Not Affected