CVE-2022-37454

NameCVE-2022-37454
DescriptionThe Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3174-1, DLA-3175-1, DSA-5267-1, DSA-5269-1, DSA-5277-1
Debian Bugs1023030

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php7.3 (PTS)buster, buster (security)7.3.31-1~deb10u1vulnerable
php7.4 (PTS)bullseye7.4.30-1+deb11u1vulnerable
bullseye (security)7.4.33-1+deb11u1fixed
php8.1 (PTS)bookworm, sid8.1.12-1fixed
pypy3 (PTS)buster7.0.0+dfsg-3fixed
bullseye7.3.5+dfsg-2+deb11u1vulnerable
bullseye (security)7.3.5+dfsg-2+deb11u2fixed
bookworm, sid7.3.9+dfsg-5fixed
pysha3 (PTS)buster1.0.2-2vulnerable
buster (security)1.0.2-2+deb10u1fixed
bullseye1.0.2-4.1vulnerable
bullseye (security)1.0.2-4.1+deb11u1fixed
python3.10 (PTS)bookworm, sid3.10.8-3vulnerable
python3.7 (PTS)buster3.7.3-2+deb10u3vulnerable
buster (security)3.7.3-2+deb10u4fixed
python3.9 (PTS)bullseye3.9.2-1vulnerable
sid3.9.13-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php7.3source(unstable)(unfixed)
php7.4sourcebullseye7.4.33-1+deb11u1DSA-5277-1
php7.4source(unstable)(unfixed)
php8.1source(unstable)8.1.12-1
pypy3sourcebuster(not affected)
pypy3sourcebullseye7.3.5+dfsg-2+deb11u2DSA-5269-1
pypy3source(unstable)7.3.9+dfsg-5
pysha3sourcebuster1.0.2-2+deb10u1DLA-3174-1
pysha3sourcebullseye1.0.2-4.1+deb11u1DSA-5267-1
pysha3source(unstable)(unfixed)1023030
python3.10source(unstable)(unfixed)unimportant
python3.7sourcebuster3.7.3-2+deb10u4DLA-3175-1
python3.7source(unstable)(unfixed)
python3.9source(unstable)(unfixed)unimportant

Notes

[buster] - pypy3 <not-affected> (Vulnerable code not present before we switch to the 3.6 branch in 7.1.1+dfsg-1)
https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658
https://github.com/XKCP/XKCP/commit/fdc6fef075f4e81d6b1bc38364248975e08e340a
https://mouha.be/sha-3-buffer-overflow/
PHP Bug: https://bugs.php.net/bug.php?id=81738
PHP fixed in: 7.4.33, 8.0.25, 8.1.12
For PHP, introduced in: https://github.com/php/php-src/commit/91663a92d1697fc30a7ba4687d73e0f63ec2baa1 (php-7.2.0alpha1)
Fixed by: https://github.com/php/php-src/commit/248f647724e385bfb8d83aa5b5a5ca3c4ee2c7fd (php-8.2.0RC5)
https://github.com/python/cpython/issues/98517
https://github.com/python/cpython/commit/0e4e058602d93b88256ff90bbef501ba20be9dd3 (3.10-branch)
https://github.com/python/cpython/commit/857efee6d2d43c5c12fc7e377ce437144c728ab8 (3.9-branch)
https://github.com/python/cpython/commit/948c6794711458fd148a3fa62296cadeeb2ed631 (3.8-branch)
https://github.com/python/cpython/commit/8088c90044ba04cd5624b278340ebf934dbee4a5 (3.7-branch)
For Python, introduced in: https://github.com/python/cpython/commit/6fe2a75b645044ca2b5dac03e8d850567b547a9a (3.6)
Versions which have the OpenSSL sha3 delegation are not affected by the issue and only ship
source-wise the bundled _sha3 XKCP module code.
OpenSSL sha3 delegation added in https://github.com/python/cpython/commit/d5b3f6b7f9fc74438009af63f1de01bd77be9385 (v3.9.0b1)
https://python-security.readthedocs.io/vuln/sha3-buffer-overflow.html
pypy3 fix: https://foss.heptapod.net/pypy/pypy/-/commit/860b897b2611a4099ef9c63ce848fdec89c74b31
check affected packages

Search for package or bug name: Reporting problems