suse · CVE-2022-45873

Quick triage

Priority: medium Published: 2022-11-25 00:40:40 UTC Updated: 2025-04-26 23:14:01 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2022-45873 severity moderate: SUSE including 26 source package names (libsystemd0, libsystemd0-32bit, …), 314 product×package rows across 39 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (39 product lines)): Known Not Affected 304, Fixed 10.

Description:

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.

cvelogic Threat Intelligence