Description
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34781 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later. |
Ubuntu USN |
USN-5583-1 | systemd vulnerability |
Ubuntu USN |
USN-5583-2 | systemd regression |
References
History
No history.
Subscriptions
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhev Hypervisor
Subscribe
Systemd Project
Subscribe
Systemd
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T00:39:08.031Z
Reserved: 2022-07-24T00:00:00.000Z
Link: CVE-2022-2526
No data.
Status : Modified
Published: 2022-09-09T15:15:10.107
Modified: 2024-11-21T07:01:11.383
Link: CVE-2022-2526
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN