CVE-2022-36227

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
libarchivelibarchive
3.0.0 ≤
𝑥
< 3.6.2
debiandebian_linux
10.0
splunkuniversal_forwarder
8.2.0 ≤
𝑥
< 8.2.12
splunkuniversal_forwarder
9.0.0 ≤
𝑥
< 9.0.6
splunkuniversal_forwarder
9.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libarchive
bookworm
3.6.2-1+deb12u1
fixed
bookworm (security)
3.6.2-1+deb12u1
fixed
bullseye
no-dsa
sid
3.7.4-1.1
fixed
trixie
3.7.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libarchive
bionic
needs-triage
focal
needed
jammy
needed
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bsdtar
suse enterprise server 15 SP4
3.5.1-150400.3.12.1
fixed
libarchive-devel
suse enterprise desktop 15 SP3
3.4.2-150200.4.15.1
fixed
suse enterprise desktop 15 SP4
3.5.1-150400.3.12.1
fixed
suse enterprise desktop 15 SP5
3.5.1-150400.3.12.1
fixed
suse enterprise desktop 15 SP6
3.7.2-150600.1.7
fixed
suse enterprise desktop 15 SP7
3.7.2-150600.3.12.1
fixed
suse enterprise sap 15 SP3
3.4.2-150200.4.15.1
fixed
suse enterprise sap 15 SP4
3.5.1-150400.3.12.1
fixed
suse enterprise sap 15 SP5
3.5.1-150400.3.12.1
fixed
suse enterprise sap 15 SP6
3.7.2-150600.1.7
fixed
suse enterprise sap 15 SP7
3.7.2-150600.3.12.1
fixed
suse enterprise server 15 SP3
3.4.2-150200.4.15.1
fixed
suse enterprise server 15 SP4
3.5.1-150400.3.12.1
fixed
suse enterprise server 15 SP5
3.5.1-150400.3.12.1
fixed
suse enterprise server 15 SP6
3.7.2-150600.1.7
fixed
suse enterprise server 15 SP7
3.7.2-150600.3.12.1
fixed
libarchive13
suse enterprise desktop 15 SP3
3.4.2-150200.4.15.1
fixed
suse enterprise desktop 15 SP4
3.5.1-150400.3.12.1
fixed
suse enterprise desktop 15 SP5
3.5.1-150400.3.12.1
fixed
suse enterprise desktop 15 SP6
3.7.2-150600.1.7
fixed
suse enterprise desktop 15 SP7
3.7.2-150600.3.12.1
fixed
suse enterprise sap 15 SP3
3.4.2-150200.4.15.1
fixed
suse enterprise sap 15 SP4
3.5.1-150400.3.12.1
fixed
suse enterprise sap 15 SP5
3.5.1-150400.3.12.1
fixed
suse enterprise sap 15 SP6
3.7.2-150600.1.7
fixed
suse enterprise sap 15 SP7
3.7.2-150600.3.12.1
fixed
suse enterprise server 15 SP3
3.4.2-150200.4.15.1
fixed
suse enterprise server 15 SP4
3.5.1-150400.3.12.1
fixed
suse enterprise server 15 SP5
3.5.1-150400.3.12.1
fixed
suse enterprise server 15 SP6
3.7.2-150600.1.7
fixed
suse enterprise server 15 SP7
3.7.2-150600.3.12.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
bsdtar
RHEL 8
0:3.3.3-5.el8
fixed
RHEL 8.6 AUS
0:3.3.3-4.el8_6
fixed
RHEL 8.6 E4S
0:3.3.3-4.el8_6
fixed
RHEL 8.6 EUS
0:3.3.3-4.el8_6
fixed
RHEL 8.6 TUS
0:3.3.3-4.el8_6
fixed
RHEL 9
0:3.5.3-4.el9
fixed
libarchive
RHEL 8
0:3.3.3-5.el8
fixed
RHEL 8.6 AUS
0:3.3.3-4.el8_6
fixed
RHEL 8.6 E4S
0:3.3.3-4.el8_6
fixed
RHEL 8.6 EUS
0:3.3.3-4.el8_6
fixed
RHEL 8.6 TUS
0:3.3.3-4.el8_6
fixed
RHEL 9
0:3.5.3-4.el9
fixed
libarchive-devel
RHEL 8
0:3.3.3-5.el8
fixed
RHEL 8.6 AUS
0:3.3.3-4.el8_6
fixed
RHEL 8.6 E4S
0:3.3.3-4.el8_6
fixed
RHEL 8.6 EUS
0:3.3.3-4.el8_6
fixed
RHEL 8.6 TUS
0:3.3.3-4.el8_6
fixed
RHEL 9
0:3.5.3-4.el9
fixed