CVE-2022-43507

Source
https://cve.org/CVERecord?id=CVE-2022-43507
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43507.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-43507
Downstream
Related
Published
2023-05-10T14:15:24.400Z
Modified
2026-02-04T03:04:34.330507Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.

References

Affected packages

Git / github.com/01org/qat_engine

Affected ranges

Type
GIT
Repo
https://github.com/01org/qat_engine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.5.0
v0.5.1
v0.5.10
v0.5.11
v0.5.12
v0.5.13
v0.5.14
v0.5.15
v0.5.16
v0.5.17
v0.5.18
v0.5.19
v0.5.2
v0.5.20
v0.5.21
v0.5.22
v0.5.23
v0.5.24
v0.5.25
v0.5.26
v0.5.27
v0.5.28
v0.5.29
v0.5.3
v0.5.30
v0.5.31
v0.5.32
v0.5.33
v0.5.34
v0.5.35
v0.5.36
v0.5.37
v0.5.38
v0.5.39
v0.5.4
v0.5.40
v0.5.41
v0.5.42
v0.5.43
v0.5.44
v0.5.45
v0.5.46
v0.5.5
v0.5.6
v0.5.7
v0.5.8
v0.5.9
v0.6.1
v0.6.10
v0.6.11
v0.6.12
v0.6.13
v0.6.14
v0.6.15
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43507.json"
vanir_signatures
[
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/01org/qat_engine/commit/1c95fd724e0b92f9e9b210db64d7cc19469f1977",
        "digest": {
            "line_hashes": [
                "270858869348280585648282979919579038338",
                "119915446071434239525493028303171176445",
                "107564049208525931793274974442155005968",
                "277365158538378222374458096953232194096",
                "78441572593013828644712200606331984101"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-43507-303c8c76",
        "deprecated": false,
        "target": {
            "file": "qat_provider.h"
        }
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/01org/qat_engine/commit/1c95fd724e0b92f9e9b210db64d7cc19469f1977",
        "digest": {
            "line_hashes": [
                "156025310930304741110189901600307719992",
                "173845976601447089807024810858292505512",
                "299562738511750442871730940615843940953",
                "179453621182462454234455446159381659246",
                "235522609912799947819646102083601092484",
                "167502685527457405980628889773506766009",
                "173254830301464810348192717058539871",
                "115977538961557300197374275310826615523",
                "145305443624317969461370421360215952251",
                "301324652803090861127289442785407937691"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2022-43507-66302fb2",
        "deprecated": false,
        "target": {
            "file": "e_qat.c"
        }
    }
]