Search

Find a vulnerability

Search criteria

    4 vulnerabilities by PyPy

    CVE-2026-76875 (GCVE-0-2026-76875)

    Vulnerability from nvd – Published: 2026-09-29 12:45 – Updated: 2026-10-02 12:07 X_Open Source
    VLAI
    Title
    PyPy pyexpat ExternalEntityParserCreate Use-After-Free
    Summary
    PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 12:07 UTC
    CWE
    Impacted products
    Vendor Product Version
    PyPy PyPy Affected: 0 , < 3.11.16 (semver)
    Affected: 3.12.0 , < 3.12.14 (semver)
    Create a notification for this product.
    Date Public
    2026-09-19 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76875",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T12:07:14.237053Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T12:07:30.652Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/pypy/pypy",
              "product": "PyPy",
              "repo": "https://github.com/pypy/pypy",
              "vendor": "PyPy",
              "versions": [
                {
                  "lessThan": "3.11.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.12.14",
                  "status": "affected",
                  "version": "3.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Fabian Wahle (Hap Security)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulnCheck"
            }
          ],
          "datePublic": "2026-09-19T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module\u0027s ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy\u0027s tracing garbage collector can free the parent\u0027s C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T12:45:19.797Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://doc.pypy.org/release-v8.0.0.html"
            },
            {
              "name": "3.12 Release Tag",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.12-v8.0.0"
            },
            {
              "name": "3.11 Release Tag",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.11-v8.0.0"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/pypy-pyexpat-externalentityparsercreate-use-after-free"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "tags": [
            "x_open-source"
          ],
          "title": "PyPy pyexpat ExternalEntityParserCreate Use-After-Free",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-76875",
        "datePublished": "2026-09-29T12:45:19.797Z",
        "dateReserved": "2026-08-19T21:47:08.936Z",
        "dateUpdated": "2026-10-02T12:07:30.652Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-37454 (GCVE-0-2022-37454)

    Vulnerability from nvd – Published: 2022-10-21 00:00 – Updated: 2025-05-08 15:03
    VLAI
    Summary
    The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-08 15:03 UTC
    CWE
    • n/a
    • CWE-190 - Integer Overflow or Wraparound
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T10:29:21.027Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20230203-0001/"
              },
              {
                "name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
              },
              {
                "name": "https://mouha.be/sha-3-buffer-overflow/",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://mouha.be/sha-3-buffer-overflow/"
              },
              {
                "name": "https://news.ycombinator.com/item?id=33281106",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=33281106"
              },
              {
                "name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
              },
              {
                "name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
              },
              {
                "name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
              },
              {
                "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
              },
              {
                "name": "https://www.debian.org/security/2022/dsa-5267",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2022/dsa-5267"
              },
              {
                "name": "https://www.debian.org/security/2022/dsa-5269",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2022/dsa-5269"
              },
              {
                "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://eprint.iacr.org/2023/331"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=35050307"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.gentoo.org/glsa/202305-02"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-37454",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-08T15:03:12.969240Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-190",
                    "description": "CWE-190 Integer Overflow or Wraparound",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-08T15:03:28.946Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "unknown",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-03T10:06:29.726Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
              "url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
            },
            {
              "name": "https://mouha.be/sha-3-buffer-overflow/",
              "url": "https://mouha.be/sha-3-buffer-overflow/"
            },
            {
              "name": "https://news.ycombinator.com/item?id=33281106",
              "url": "https://news.ycombinator.com/item?id=33281106"
            },
            {
              "name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
              "url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
            },
            {
              "name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
              "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
            },
            {
              "name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
              "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
            },
            {
              "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
            },
            {
              "name": "https://www.debian.org/security/2022/dsa-5267",
              "url": "https://www.debian.org/security/2022/dsa-5267"
            },
            {
              "name": "https://www.debian.org/security/2022/dsa-5269",
              "url": "https://www.debian.org/security/2022/dsa-5269"
            },
            {
              "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
            },
            {
              "url": "https://eprint.iacr.org/2023/331"
            },
            {
              "url": "https://news.ycombinator.com/item?id=35050307"
            },
            {
              "url": "https://security.gentoo.org/glsa/202305-02"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-37454",
        "datePublished": "2022-10-21T00:00:00.000Z",
        "dateReserved": "2022-08-07T00:00:00.000Z",
        "dateUpdated": "2025-05-08T15:03:28.946Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-76875 (GCVE-0-2026-76875)

    Vulnerability from cvelistv5 – Published: 2026-09-29 12:45 – Updated: 2026-10-02 12:07 X_Open Source
    VLAI
    Title
    PyPy pyexpat ExternalEntityParserCreate Use-After-Free
    Summary
    PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 12:07 UTC
    CWE
    Impacted products
    Vendor Product Version
    PyPy PyPy Affected: 0 , < 3.11.16 (semver)
    Affected: 3.12.0 , < 3.12.14 (semver)
    Create a notification for this product.
    Date Public
    2026-09-19 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76875",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T12:07:14.237053Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T12:07:30.652Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/pypy/pypy",
              "product": "PyPy",
              "repo": "https://github.com/pypy/pypy",
              "vendor": "PyPy",
              "versions": [
                {
                  "lessThan": "3.11.16",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "3.12.14",
                  "status": "affected",
                  "version": "3.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Fabian Wahle (Hap Security)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulnCheck"
            }
          ],
          "datePublic": "2026-09-19T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module\u0027s ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy\u0027s tracing garbage collector can free the parent\u0027s C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T12:45:19.797Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://doc.pypy.org/release-v8.0.0.html"
            },
            {
              "name": "3.12 Release Tag",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.12-v8.0.0"
            },
            {
              "name": "3.11 Release Tag",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/pypy/pypy/releases/tag/release-pypy3.11-v8.0.0"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/pypy-pyexpat-externalentityparsercreate-use-after-free"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "tags": [
            "x_open-source"
          ],
          "title": "PyPy pyexpat ExternalEntityParserCreate Use-After-Free",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-76875",
        "datePublished": "2026-09-29T12:45:19.797Z",
        "dateReserved": "2026-08-19T21:47:08.936Z",
        "dateUpdated": "2026-10-02T12:07:30.652Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-37454 (GCVE-0-2022-37454)

    Vulnerability from cvelistv5 – Published: 2022-10-21 00:00 – Updated: 2025-05-08 15:03
    VLAI
    Summary
    The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-08 15:03 UTC
    CWE
    • n/a
    • CWE-190 - Integer Overflow or Wraparound
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T10:29:21.027Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20230203-0001/"
              },
              {
                "name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
              },
              {
                "name": "https://mouha.be/sha-3-buffer-overflow/",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://mouha.be/sha-3-buffer-overflow/"
              },
              {
                "name": "https://news.ycombinator.com/item?id=33281106",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=33281106"
              },
              {
                "name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
              },
              {
                "name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
              },
              {
                "name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
              },
              {
                "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
              },
              {
                "name": "https://www.debian.org/security/2022/dsa-5267",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2022/dsa-5267"
              },
              {
                "name": "https://www.debian.org/security/2022/dsa-5269",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2022/dsa-5269"
              },
              {
                "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://eprint.iacr.org/2023/331"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=35050307"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.gentoo.org/glsa/202305-02"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-37454",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-08T15:03:12.969240Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-190",
                    "description": "CWE-190 Integer Overflow or Wraparound",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-08T15:03:28.946Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "unknown",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-05-03T10:06:29.726Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
              "url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
            },
            {
              "name": "https://mouha.be/sha-3-buffer-overflow/",
              "url": "https://mouha.be/sha-3-buffer-overflow/"
            },
            {
              "name": "https://news.ycombinator.com/item?id=33281106",
              "url": "https://news.ycombinator.com/item?id=33281106"
            },
            {
              "name": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
              "url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
            },
            {
              "name": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
              "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
            },
            {
              "name": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
              "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
            },
            {
              "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
            },
            {
              "name": "https://www.debian.org/security/2022/dsa-5267",
              "url": "https://www.debian.org/security/2022/dsa-5267"
            },
            {
              "name": "https://www.debian.org/security/2022/dsa-5269",
              "url": "https://www.debian.org/security/2022/dsa-5269"
            },
            {
              "name": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
            },
            {
              "url": "https://eprint.iacr.org/2023/331"
            },
            {
              "url": "https://news.ycombinator.com/item?id=35050307"
            },
            {
              "url": "https://security.gentoo.org/glsa/202305-02"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2022-37454",
        "datePublished": "2022-10-21T00:00:00.000Z",
        "dateReserved": "2022-08-07T00:00:00.000Z",
        "dateUpdated": "2025-05-08T15:03:28.946Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }