Description
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Published: 2022-11-23
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-48725 systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
Ubuntu USN Ubuntu USN USN-5928-1 systemd vulnerabilities
History

Fri, 25 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Fedoraproject Fedora
Redhat Enterprise Linux
Systemd Project Systemd
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-25T18:19:52.554Z

Reserved: 2022-11-23T00:00:00.000Z

Link: CVE-2022-45873

cve-icon Vulnrichment

Updated: 2024-08-03T14:24:03.197Z

cve-icon NVD

Status : Modified

Published: 2022-11-23T23:15:10.183

Modified: 2025-04-25T19:15:48.487

Link: CVE-2022-45873

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-10-18T00:00:00Z

Links: CVE-2022-45873 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses