Apport's is_closing_session() Function Allows RAM Consumption in Apport Process
CVE-2022-28656

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 June 2024

Summary

A vulnerability exists in the Apport error reporting tool used in Ubuntu that allows users to consume an excessive amount of RAM through the is_closing_session() function. This misuse can lead to degraded system performance and may affect the overall stability of the operating environment. Administrators must be vigilant in applying updates and monitoring system resources to mitigate such risks.

Affected Version(s)

Apport Linux 0 < 2.21.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Gerrit Venema
.