Bugzilla – Bug 1214576
VUL-0: CVE-2022-26592: libsass: Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector:has_real_parent_ref function.
Last modified: 2024-01-02 13:30:29 UTC
CVE-2022-26592 Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-26592 https://www.cve.org/CVERecord?id=CVE-2022-26592 https://github.com/sass/libsass/issues/3174
No change in upstream bug.
No news in upstream bug.
I did some research and commented my findings at: https://github.com/sass/libsass/issues/3177#issuecomment-1854445404 And could motivate upstream maintainer Marcel Greter to provide: https://github.com/sass/libsass/pull/3184 which fixes this issue. I backported these changes as libsass-CVE-2022-43357,CVE-2022-43358,CVE-2022-26592.patch and ran them against all 3 POCs, which are now solved. SR#1133374 to devel:libraries:c_c++/libsass SR#315778 to SUSE_SLE-15-SP2_Update
SUSE-SU-2023:4895-1: An update that solves three vulnerabilities can now be installed. Category: security (moderate) Bug References: 1214573, 1214575, 1214576 CVE References: CVE-2022-26592, CVE-2022-43357, CVE-2022-43358 Sources used: SUSE Package Hub 15 15-SP4 (src): libsass-3.6.5-150200.4.10.1 SUSE Package Hub 15 15-SP5 (src): libsass-3.6.5-150200.4.10.1 openSUSE Leap 15.4 (src): libsass-3.6.5-150200.4.10.1 openSUSE Leap 15.5 (src): libsass-3.6.5-150200.4.10.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.