CVE-2022-0367: Buffer Overflow
A flaw was found in libmodbus. A heap-based buffer overflow in modbusreceivemsg.
References:
https://github.com/stephane/libmodbus/issues/614
Other sources
A heap-based buffer overflow flaw was found in libmodbus in function modbusreply() in src/modbus.c.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0367?
CVE-2022-0367 is a heap-based buffer overflow vulnerability found in libmodbus.
Where is the vulnerability located?
The vulnerability is located in the modbus_reply() function in src/modbus.c of the libmodbus library.
Which software is affected by CVE-2022-0367?
The vulnerability affects libmodbus version up to and excluding 3.1.7, Fedoraproject Extra Packages For Enterprise Linux 7.0, Fedoraproject Fedora 35, and Debian Debian Linux 10.0.
What is the severity of CVE-2022-0367?
The severity of CVE-2022-0367 is high with a score of 7.8 (CVSS base score).
How can I fix CVE-2022-0367?
To fix CVE-2022-0367, users should update to a version of libmodbus higher than 3.1.7 or apply the necessary patches provided by the vendor.