CVE-2022-28654: Medium severity ubuntu python3-apport vulnerability
Published Jun 4, 2024
·Updated
isclosingsession() allows users to fill up apport.log
Affected Software
5 affected components
Apport Project Apport<2.21.0
Ubuntu=18.04
Ubuntu=20.04
Ubuntu=21.10
Ubuntu=22.04
Event History
Jun 4, 2024
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
Description
Jun 7, 2024
Data Sourced
via Debian·06:52 PM
DescriptionAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·06:57 PM
Description
Aug 22, 2025
Data Sourced
via Ubuntu·04:44 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-28654?
CVE-2022-28654 is classified as a high-severity vulnerability affecting multiple versions of Apport in Ubuntu.
2
How do I fix CVE-2022-28654?
To fix CVE-2022-28654, users should update Apport to version 2.21.0 or later.
3
What systems are affected by CVE-2022-28654?
CVE-2022-28654 affects Apport running on Ubuntu 18.04, 20.04, 21.10, and 22.04.
4
What does CVE-2022-28654 exploit?
CVE-2022-28654 exploits an issue in the is_closing_session() function that can lead to excessive logging in apport.log.
5
Are there any workarounds for CVE-2022-28654?
Currently, the recommended approach is to apply the necessary updates to mitigate CVE-2022-28654 effectively.