CVE-2022-2526

A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
Configurations

Configuration 1 (hide)

cpe:2.3:a:systemd_project:systemd:240:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

History

20 Jan 2023, 03:17

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20221111-0005/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20221111-0005/ - Third Party Advisory
CPE cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
First Time Netapp active Iq Unified Manager
Netapp h500s
Netapp h700s
Netapp h700s Firmware
Netapp
Netapp h410s
Netapp h300s Firmware
Netapp h500s Firmware
Netapp h300s
Netapp h410s Firmware

14 Nov 2022, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20221111-0005/ -

15 Sep 2022, 17:29

Type Values Removed Values Added
CPE cpe:2.3:a:systemd_project:systemd:240:*:*:*:*:*:*:*
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Systemd Project systemd
Systemd Project
References (MISC) https://github.com/systemd/systemd/commit/d973d94dec349fb676fdd844f6fe2ada3538f27c - (MISC) https://github.com/systemd/systemd/commit/d973d94dec349fb676fdd844f6fe2ada3538f27c - Patch, Third Party Advisory

09 Sep 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-09 15:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-2526

Mitre link : CVE-2022-2526

CVE.ORG link : CVE-2022-2526


JSON object : View

Products Affected

netapp

  • h500s
  • h700s_firmware
  • h410s
  • h500s_firmware
  • h300s
  • h700s
  • h300s_firmware
  • active_iq_unified_manager
  • h410s_firmware

systemd_project

  • systemd
CWE
CWE-416

Use After Free