CVE Vulnerabilities

CVE-2022-3821

Off-by-one Error

Published: Nov 08, 2022 | Modified: May 02, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
SystemdSystemd_project*251 (including)
Red Hat Enterprise Linux 8RedHatsystemd-0:239-68.el8_7.1*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatsystemd-0:239-58.el8_6.13*
Red Hat Enterprise Linux 9RedHatsystemd-0:250-12.el9_1.1*
Red Hat Enterprise Linux 9RedHatsystemd-0:250-12.el9_1.1*
SystemdUbuntubionic*
SystemdUbuntuesm-infra-legacy/trusty*
SystemdUbuntuesm-infra/bionic*
SystemdUbuntuesm-infra/focal*
SystemdUbuntuesm-infra/xenial*
SystemdUbuntufocal*
SystemdUbuntujammy*
SystemdUbuntutrusty*
SystemdUbuntutrusty/esm*
SystemdUbuntuxenial*

Potential Mitigations

References