CVE-2022-28656: Medium severity ubuntu python3-apport vulnerability
Published Jun 4, 2024
·Updated
isclosingsession() allows users to consume RAM in the Apport process
Affected Software
5 affected components
Apport Project Apport<2.21.0
Ubuntu=18.04
Ubuntu=20.04
Ubuntu=21.10
Ubuntu=22.04
Event History
Jun 4, 2024
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
Description
Jun 7, 2024
Data Sourced
via Debian·06:52 PM
DescriptionAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·06:57 PM
Description
Sep 3, 2025
Data Sourced
via Ubuntu·04:46 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-28656?
CVE-2022-28656 is classified as a moderate severity vulnerability due to its potential impact on system performance.
2
How do I fix CVE-2022-28656?
To fix CVE-2022-28656, upgrade to Apport version 2.21.0 or later.
3
What systems are affected by CVE-2022-28656?
CVE-2022-28656 affects Apport in various versions of Ubuntu Linux including 18.04, 20.04, 21.10, and 22.04.
4
What type of vulnerability is CVE-2022-28656?
CVE-2022-28656 is a resource consumption vulnerability allowing users to exploit the is_closing_session() function.
5
Is CVE-2022-28656 exploitable remotely?
CVE-2022-28656 may be exploited locally, as it requires access to the Apport process.