CVE-2022-28655: High severity ubuntu python3-apport vulnerability
Published Jun 4, 2024
·Updated
isclosingsession() allows users to create arbitrary tcp dbus connections
Affected Software
5 affected components
Apport Project Apport<2.21.0
Ubuntu=18.04
Ubuntu=20.04
Ubuntu=21.10
Ubuntu=22.04
Event History
Jun 4, 2024
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
Description
Jun 7, 2024
Data Sourced
via Debian·06:52 PM
DescriptionAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·06:57 PM
Description
Aug 22, 2025
Data Sourced
via Ubuntu·04:44 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-28655?
CVE-2022-28655 is classified as a medium severity vulnerability due to its potential for exploitation in a local environment.
2
How do I fix CVE-2022-28655?
To fix CVE-2022-28655, update Apport to version 2.21.0 or later on affected Ubuntu systems.
3
Which systems are affected by CVE-2022-28655?
CVE-2022-28655 affects Apport versions prior to 2.21.0 on Ubuntu 18.04, 20.04, 21.10, and 22.04.
4
What is the impact of CVE-2022-28655?
The impact of CVE-2022-28655 allows unauthorized users to create arbitrary TCP D-Bus connections, posing a risk to system integrity.
5
Is CVE-2022-28655 being actively exploited?
As of now, there have been no confirmed reports of active exploitation of CVE-2022-28655.