CVE-2022-47022

NameCVE-2022-47022
DescriptionAn issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of service or other unspecified impacts via glibc-cpuset in topology-linux.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hwloc (PTS)buster1.11.12-3vulnerable
bullseye2.4.1+dfsg-1vulnerable
bookworm2.9.0-1vulnerable
sid, trixie2.10.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hwlocsource(unstable)2.9.3-1

Notes

[bookworm] - hwloc <no-dsa> (Minor issue)
[bullseye] - hwloc <no-dsa> (Minor issue)
[buster] - hwloc <no-dsa> (Minor issue)
https://github.com/open-mpi/hwloc/issues/544
https://github.com/open-mpi/hwloc/commit/ac1f8db9a0790d2bf153711ff4cbf6101f89aace (master)
https://github.com/open-mpi/hwloc/commit/a62b8ba587b225d25d6ee05c705fbc44c55d1986 (hwloc-2.9.3rc1)
Additionally openmpi and mpich embedd hwloc, but issue seems negligible

Search for package or bug name: Reporting problems