CVE Database
/

CVE-2022-2526

Back to search

CVE-2022-2526

Published: Sep 9, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.

VendorProductVersions

n/a

systemd-resolved

affected
systemd 240

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now