Bug 1218749 (CVE-2022-48620)

Summary: VUL-0: CVE-2022-48620: libuev: uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.
Product: [openSUSE] openSUSE Distribution Reporter: SMASH SMASH <smash_bz>
Component: SecurityAssignee: Security Team bot <security-team>
Status: IN_PROGRESS --- QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: amajer, stoyan.manolov, thomas.leroy
Version: Leap 15.6   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/390989/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 2 Michael Vetter 2024-01-12 08:55:46 UTC
SR#1138233 to devel:libraries:c_c++/libuev
SR#1138234 to openSUSE_Backports_SLE-15-SP5_Update
Comment 3 OBSbugzilla Bot 2024-01-12 09:35:01 UTC
This is an autogenerated message for OBS integration:
This bug (1218749) was mentioned in
https://build.opensuse.org/request/show/1138234 Backports:SLE-15-SP5 / libuev
Comment 4 Marcus Meissner 2024-01-18 20:04:54 UTC
openSUSE-SU-2024:0023-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1218749
CVE References: CVE-2022-48620
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    libuev-2.4.1-bp155.3.3.1