sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated for the buffer representing system activities. This issue may lead to Remote Code Execution (RCE). This issue has been patched in version 12.7.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3188-1 | sysstat security update |
Debian DLA |
DLA-3434-1 | sysstat security update |
Debian DLA |
DLA-4336-1 | sysstat security update |
EUVD |
EUVD-2022-41838 | sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated for the buffer representing system activities. This issue may lead to Remote Code Execution (RCE). This issue has been patched in version 12.7.1. |
Ubuntu USN |
USN-5735-1 | Sysstat vulnerability |
Ubuntu USN |
USN-5748-1 | Sysstat vulnerability |
Ubuntu USN |
USN-6145-1 | Sysstat vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 22 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T17:31:00.911Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39377
Updated: 2025-11-03T17:31:00.911Z
Status : Modified
Published: 2022-11-08T20:15:11.193
Modified: 2025-11-03T18:15:39.970
Link: CVE-2022-39377
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN