CVE-2022-26291: Use After Free
Published Mar 28, 2022
·Updated
lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaqdecompressbuf() and clearrulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.
Affected Software
5 affected componentsFixes available
debian/lrzip
0.631+git180528-1+deb10u10.641-1+deb11u10.651-2
Long Range Zip Project Long Range Zip=0.641
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Mar 28, 2022
CVE Published
via MITRE·09:52 PM
Data Sourced
via MITRE·09:52 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this lrzip vulnerability?
The vulnerability ID for this lrzip vulnerability is CVE-2022-26291.
2
What is the severity of CVE-2022-26291?
CVE-2022-26291 has a severity level of medium with a value of 5.5.
3
What is the affected software for CVE-2022-26291?
The affected software for CVE-2022-26291 is lrzip v0.641.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers using a crafted Irz file to cause a Denial of Service (DoS) through a multiple concurrency use-after-free.
5
How can I fix CVE-2022-26291?
To fix CVE-2022-26291, update to one of the following versions: lrzip v0.631+git180528-1+deb10u1, lrzip v0.641-1+deb11u1, or lrzip v0.651-2.