Bug 1203522 - (CVE-2022-40153) VUL-0: CVE-2022-40153: xstream: stackoverflow in XML serialization
(CVE-2022-40153)
VUL-0: CVE-2022-40153: xstream: stackoverflow in XML serialization
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/342790/
CVSSv3.1:SUSE:CVE-2022-40153:5.9:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-09-19 11:40 UTC by Thomas Leroy
Modified: 2022-10-12 09:08 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
stoyan.manolov: needinfo? (fstrba)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-09-19 11:40:28 UTC
CVE-2022-40153

Those using Xstream to seralize XML data may be vulnerable to Denial of Service
attacks (DOS). If the parser is running on user supplied input, an attacker may
supply content that causes the parser to crash by stackoverflow. This effect may
support a denial of service attack.

Upstream issue:
https://github.com/x-stream/xstream/issues/304

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-40153
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=49858
https://github.com/x-stream/xstream/issues/304
https://www.cve.org/CVERecord?id=CVE-2022-40153
Comment 1 Thomas Leroy 2022-09-19 11:40:41 UTC
Upstream issue is being discussed. Tracking SUSE:SLE-15-SP2:Update as affected
by default