CVE-2022-26083

NameCVE-2022-26083
DescriptionGeneration of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ipp-crypto (PTS)sid, trixie2021.12.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ipp-cryptosource(unstable)(not affected)

Notes

- ipp-crypto <not-affected> (Fixed before initial upload to Debian)
https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00667.html

Search for package or bug name: Reporting problems