CVE Vulnerabilities

CVE-2022-31291

Double Free

Published: Jun 16, 2022 | Modified: Feb 03, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Diagnostic_log_and_trace Genivi 2.18.8 (including) 2.18.8 (including)
Dlt-daemon Ubuntu impish *
Dlt-daemon Ubuntu kinetic *
Dlt-daemon Ubuntu lunar *
Dlt-daemon Ubuntu mantic *

Potential Mitigations

References