Unrated severityNVD Advisory· Published Nov 8, 2022· Updated May 2, 2025
CVE-2022-3821
CVE-2022-3821
Description
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
Affected products
37- Systemd/Systemddescription
- osv-coords36 versionspkg:apk/chainguard/py3.10-systemdpkg:apk/chainguard/py3.11-systemdpkg:apk/chainguard/py3.12-systemdpkg:apk/chainguard/py3.13-systemdpkg:apk/chainguard/py3-supported-systemdpkg:apk/chainguard/py3-systemdpkg:rpm/almalinux/systemdpkg:rpm/almalinux/systemd-containerpkg:rpm/almalinux/systemd-develpkg:rpm/almalinux/systemd-journal-remotepkg:rpm/almalinux/systemd-libspkg:rpm/almalinux/systemd-oomdpkg:rpm/almalinux/systemd-pampkg:rpm/almalinux/systemd-resolvedpkg:rpm/almalinux/systemd-rpm-macrospkg:rpm/almalinux/systemd-testspkg:rpm/almalinux/systemd-udevpkg:rpm/opensuse/systemd&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/systemd&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/systemd&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/opensuse/systemd&distro=openSUSE%20Tumbleweedpkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-ESPOSpkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/systemd&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 0+ 35 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 250-12.el9_1.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 250-12.el9_1.1
- (no CPE)range: < 250-12.el9_1.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 239-68.el8_7.1
- (no CPE)range: < 246.16-150300.7.54.1
- (no CPE)range: < 249.12-150400.8.13.1
- (no CPE)range: < 246.16-150300.7.54.1
- (no CPE)range: < 254.5-3.1
- (no CPE)range: < 246.16-150300.7.54.1
- (no CPE)range: < 246.16-150300.7.54.1
- (no CPE)range: < 249.12-150400.8.13.1
- (no CPE)range: < 246.16-150300.7.54.1
- (no CPE)range: < 249.12-150400.8.13.1
- (no CPE)range: < 228-150.108.2
- (no CPE)range: < 228-150.108.2
- (no CPE)range: < 228-150.108.2
- (no CPE)range: < 228-157.43.2
- (no CPE)range: < 228-150.108.2
- (no CPE)range: < 228-157.43.2
- (no CPE)range: < 228-157.43.2
- (no CPE)range: < 254.18-1.1
- (no CPE)range: < 228-150.108.2
- (no CPE)range: < 228-150.108.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVBQC2VLSDVQAPJTEMTREXDL4HYLXG2P/mitrevendor-advisory
- security.gentoo.org/glsa/202305-15mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/06/msg00036.htmlmitremailing-list
- bugzilla.redhat.com/show_bug.cgimitre
- github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4emitre
- github.com/systemd/systemd/issues/23928mitre
- github.com/systemd/systemd/pull/23933mitre
News mentions
0No linked articles in our index yet.