CVE-2022-28658: Medium severity ubuntu python3-apport vulnerability
Published Jun 4, 2024
·Updated
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
Affected Software
5 affected components
Apport Project Apport<2.21.0
Ubuntu=18.04
Ubuntu=20.04
Ubuntu=21.10
Ubuntu=22.04
Event History
Jun 4, 2024
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
Description
Jun 7, 2024
Data Sourced
via Debian·06:52 PM
DescriptionAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·06:57 PM
Description
Aug 30, 2025
Data Sourced
via Ubuntu·04:45 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-28658?
CVE-2022-28658 has a high severity rating due to its potential for argument spoofing.
2
How do I fix CVE-2022-28658?
To fix CVE-2022-28658, upgrade Apport to version 2.21.0 or later.
3
Which software is affected by CVE-2022-28658?
CVE-2022-28658 affects Apport versions prior to 2.21.0 and specific Ubuntu Linux versions.
4
Can CVE-2022-28658 be exploited remotely?
CVE-2022-28658 requires local access to exploit, making remote exploitation unlikely.
5
What platforms are impacted by CVE-2022-28658?
CVE-2022-28658 impacts Ubuntu Linux versions 18.04, 20.04, 21.10, and 22.04 with vulnerable Apport versions.