CVE-2022-28657: High severity ubuntu python3-apport vulnerability
Published Jun 4, 2024
·Updated
Apport does not disable python crash handler before entering chroot
Affected Software
5 affected components
Apport Project Apport<2.21.0
Ubuntu=18.04
Ubuntu=20.04
Ubuntu=21.10
Ubuntu=22.04
Event History
Jun 4, 2024
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
Description
Jun 11, 2024
Data Sourced
via Debian·06:53 PM
DescriptionAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·06:57 PM
Description
Sep 3, 2025
Data Sourced
via Ubuntu·04:46 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-28657?
CVE-2022-28657 has a medium severity rating due to the potential for privilege escalation.
2
What versions of Apport are affected by CVE-2022-28657?
CVE-2022-28657 affects Apport versions earlier than 2.21.0.
3
How do I fix CVE-2022-28657?
To fix CVE-2022-28657, upgrade Apport to version 2.21.0 or later.
4
Which Ubuntu versions are vulnerable to CVE-2022-28657?
CVE-2022-28657 affects Ubuntu versions 18.04, 20.04, 21.10, and 22.04.
5
What is the nature of the vulnerability in CVE-2022-28657?
CVE-2022-28657 involves Apport not disabling the Python crash handler before entering a chroot environment.