CVE-2022-39377: sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow
sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocatestructures contains a sizet overflow in sacommon.c. The allocatestructures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated for the buffer representing system activities. This issue may lead to Remote Code Execution (RCE). This issue has been patched in version 12.7.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-39377.
What is the severity of CVE-2022-39377?
The severity of CVE-2022-39377 is high.
What is the affected software?
The affected software includes sysstat versions 9.1.16 to 12.6.1, Debian Linux 10.0, and Fedora 35, 36, and 37.
What is the CWE ID of CVE-2022-39377?
The CWE ID of CVE-2022-39377 is CWE-120 and CWE-131.
Are there any references available for CVE-2022-39377?
Yes, there are references available for CVE-2022-39377. You can find them [here](https://github.com/sysstat/sysstat/security/advisories/GHSA-q8r6-g56f-9w7x), [here](https://lists.debian.org/debian-lts-announce/2022/11/msg00014.html), and [here](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6F26ALXWYHT4LN2AHPZM34OQEXTJE3JZ/).