UBUNTU-CVE-2022-31169

Source
https://ubuntu.com/security/CVE-2022-31169
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-31169.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-31169
Related
Published
2022-07-22T04:15:00Z
Modified
2022-07-22T04:15:00Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 targets where constant divisors can result in incorrect division results at runtime. This affects Wasmtime prior to version 0.38.2 and Cranelift prior to 0.85.2. This issue only affects the AArch64 platform. Other platforms are not affected. The translation rules for constants did not take into account whether sign or zero-extension should happen which resulted in an incorrect value being placed into a register when a division was encountered. The impact of this bug is that programs executing within the WebAssembly sandbox would not behave according to the WebAssembly specification. This means that it is hypothetically possible for execution within the sandbox to go awry and WebAssembly programs could produce unexpected results. This should not impact hosts executing WebAssembly but does affect the correctness of guest programs. This bug has been patched in Wasmtime version 0.38.2 and cranelift-codegen 0.85.2. There are no known workarounds.

References

Affected packages

Ubuntu:Pro:18.04:LTS / mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*

52.3.1-0ubuntu3
52.3.1-7fakesync1
52.8.1-0ubuntu0.18.04.1
52.9.1-0ubuntu0.18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / mozjs38

Package

Name
mozjs38
Purl
pkg:deb/ubuntu/mozjs38?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

38.*

38.8.0~repack1-0ubuntu1
38.8.0~repack1-0ubuntu3
38.8.0~repack1-0ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

69.*

69.0.3+build1-0ubuntu1

70.*

70.0+build2-0ubuntu1
70.0+build2-0ubuntu2
70.0.1+build1-0ubuntu2

71.*

71.0+build2-0ubuntu2
71.0+build5-0ubuntu1

72.*

72.0.1+build1-0ubuntu1
72.0.2+build1-0ubuntu1

73.*

73.0+build1-0ubuntu1
73.0+build2-0ubuntu1
73.0+build3-0ubuntu1
73.0.1+build1-0ubuntu1

74.*

74.0+build1-0ubuntu1
74.0+build2-0ubuntu1
74.0+build2-0ubuntu2
74.0+build3-0ubuntu1

75.*

75.0+build3-0ubuntu1

76.*

76.0+build2-0ubuntu0.20.04.1
76.0.1+build1-0ubuntu0.20.04.1

77.*

77.0.1+build1-0ubuntu0.20.04.1

78.*

78.0.1+build1-0ubuntu0.20.04.1
78.0.2+build2-0ubuntu0.20.04.1

79.*

79.0+build1-0ubuntu0.20.04.1

80.*

80.0+build2-0ubuntu0.20.04.1
80.0.1+build1-0ubuntu0.20.04.1

81.*

81.0+build2-0ubuntu0.20.04.1
81.0.2+build1-0ubuntu0.20.04.1

82.*

82.0+build2-0ubuntu0.20.04.1
82.0.2+build1-0ubuntu0.20.04.1
82.0.3+build1-0ubuntu0.20.04.1

83.*

83.0+build2-0ubuntu0.20.04.1

84.*

84.0+build3-0ubuntu0.20.04.1
84.0.1+build1-0ubuntu0.20.04.1
84.0.2+build1-0ubuntu0.20.04.1

85.*

85.0+build1-0ubuntu0.20.04.1
85.0.1+build1-0ubuntu0.20.04.1

86.*

86.0+build3-0ubuntu0.20.04.1
86.0.1+build1-0ubuntu0.20.04.1

87.*

87.0+build3-0ubuntu0.20.04.2

88.*

88.0+build2-0ubuntu0.20.04.1
88.0.1+build1-0ubuntu0.20.04.2

89.*

89.0+build2-0ubuntu0.20.04.2
89.0.1+build1-0ubuntu0.20.04.1
89.0.2+build1-0ubuntu0.20.04.1

90.*

90.0+build1-0ubuntu0.20.04.1
90.0.2+build1-0ubuntu0.20.04.1

91.*

91.0+build2-0ubuntu0.20.04.1
91.0.1+build1-0ubuntu0.20.04.1
91.0.2+build1-0ubuntu0.20.04.1

92.*

92.0+build3-0ubuntu0.20.04.1

93.*

93.0+build1-0ubuntu0.20.04.1

94.*

94.0+build3-0ubuntu0.20.04.1

95.*

95.0+build1-0ubuntu0.20.04.1
95.0.1+build2-0ubuntu0.20.04.1

96.*

96.0+build2-0ubuntu0.20.04.1

97.*

97.0+build2-0ubuntu0.20.04.1
97.0.2+build1-0ubuntu0.20.04.1

98.*

98.0+build3-0ubuntu0.20.04.2
98.0.1+build2-0ubuntu0.20.04.1
98.0.2+build1-0ubuntu0.20.04.1

99.*

99.0+build2-0ubuntu0.20.04.2

100.*

100.0+build2-0ubuntu0.20.04.1
100.0.2+build1-0ubuntu0.20.04.1

101.*

101.0.1+build1-0ubuntu0.20.04.1

102.*

102.0+build2-0ubuntu0.20.04.1

103.*

103.0+build1-0ubuntu0.20.04.1

104.*

104.0+build3-0ubuntu0.20.04.1

105.*

105.0+build2-0ubuntu0.20.04.1

106.*

106.0.2+build1-0ubuntu0.20.04.1
106.0.5+build1-0ubuntu0.20.04.1

107.*

107.0+build2-0ubuntu0.20.04.1

108.*

108.0+build2-0ubuntu0.20.04.1
108.0.1+build1-0ubuntu0.20.04.1
108.0.2+build1-0ubuntu0.20.04.1

109.*

109.0+build2-0ubuntu0.20.04.1
109.0.1+build1-0ubuntu0.20.04.2

110.*

110.0+build3-0ubuntu0.20.04.1
110.0.1+build2-0ubuntu0.20.04.1

111.*

111.0+build2-0ubuntu0.20.04.1
111.0.1+build2-0ubuntu0.20.04.1

112.*

112.0+build2-0ubuntu0.20.04.1
112.0.1+build1-0ubuntu0.20.04.1
112.0.2+build1-0ubuntu0.20.04.1

113.*

113.0+build2-0ubuntu0.20.04.1
113.0.1+build1-0ubuntu0.20.04.1
113.0.2+build1-0ubuntu0.20.04.1

114.*

114.0+build3-0ubuntu0.20.04.1
114.0.1+build1-0ubuntu0.20.04.1
114.0.2+build1-0ubuntu0.20.04.1

115.*

115.0+build2-0ubuntu0.20.04.3
115.0.2+build1-0ubuntu0.20.04.1

116.*

116.0+build2-0ubuntu0.20.04.2
116.0.2+build1-0ubuntu0.20.04.1
116.0.3+build2-0ubuntu0.20.04.1

117.*

117.0+build2-0ubuntu0.20.04.1
117.0.1+build2-0ubuntu0.20.04.1

118.*

118.0.1+build1-0ubuntu0.20.04.1
118.0.2+build2-0ubuntu0.20.04.1

119.*

119.0+build2-0ubuntu0.20.04.1
119.0.1+build1-0ubuntu0.20.04.1

120.*

120.0+build2-0ubuntu0.20.04.1
120.0.1+build1-0ubuntu0.20.04.1

121.*

121.0+build1-0ubuntu0.20.04.1
121.0.1+build1-0ubuntu0.20.04.1

122.*

122.0+build2-0ubuntu0.20.04.1
122.0.1+build1-0ubuntu0.20.04.1

123.*

123.0+build3-0ubuntu0.20.04.1
123.0.1+build1-0ubuntu0.20.04.1

124.*

124.0+build1-0ubuntu0.20.04.1
124.0.1+build1-0ubuntu0.20.04.1
124.0.2+build1-0ubuntu0.20.04.1

125.*

125.0.2+build1-0ubuntu0.20.04.2
125.0.3+build1-0ubuntu0.20.04.1

126.*

126.0+build2-0ubuntu0.20.04.1
126.0.1+build1-0ubuntu0.20.04.1

127.*

127.0.2+build1-0ubuntu0.20.04.1

128.*

128.0+build2-0ubuntu0.20.04.1

129.*

129.0.1+build1-0ubuntu0.20.04.1
129.0.2+build1-0ubuntu0.20.04.1

130.*

130.0+build2-0ubuntu0.20.04.1
130.0.1+build1-0ubuntu0.20.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mozjs52

Package

Name
mozjs52
Purl
pkg:deb/ubuntu/mozjs52?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

52.*

52.9.1-1build1
52.9.1-1ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / mozjs68

Package

Name
mozjs68
Purl
pkg:deb/ubuntu/mozjs68?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

68.*

68.5.0-1~fakesync
68.5.0-2~fakesync
68.6.0-1
68.6.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:68.*

1:68.1.2+build1-0ubuntu1
1:68.1.2+build1-0ubuntu2
1:68.2.1+build1-0ubuntu1
1:68.2.2+build1-0ubuntu1
1:68.3.0+build2-0ubuntu1
1:68.3.1+build1-0ubuntu2
1:68.4.1+build1-0ubuntu1
1:68.4.2+build2-0ubuntu1
1:68.5.0+build1-0ubuntu1
1:68.6.0+build2-0ubuntu1
1:68.7.0+build1-0ubuntu1
1:68.7.0+build1-0ubuntu2
1:68.8.0+build2-0ubuntu0.20.04.2
1:68.10.0+build1-0ubuntu0.20.04.1

1:78.*

1:78.7.1+build1-0ubuntu0.20.04.1
1:78.8.1+build1-0ubuntu0.20.04.1
1:78.11.0+build1-0ubuntu0.20.04.2
1:78.13.0+build1-0ubuntu0.20.04.2
1:78.14.0+build1-0ubuntu0.20.04.1
1:78.14.0+build1-0ubuntu0.20.04.2

1:91.*

1:91.5.0+build1-0ubuntu0.20.04.1
1:91.7.0+build2-0ubuntu0.20.04.1
1:91.8.1+build1-0ubuntu0.20.04.1
1:91.9.1+build1-0ubuntu0.20.04.1
1:91.11.0+build2-0ubuntu0.20.04.1

1:102.*

1:102.2.2+build1-0ubuntu0.20.04.1
1:102.4.2+build2-0ubuntu0.20.04.1
1:102.7.1+build2-0ubuntu0.20.04.1
1:102.8.0+build2-0ubuntu0.20.04.1
1:102.9.0+build1-0ubuntu0.20.04.1
1:102.10.0+build2-0ubuntu0.20.04.1
1:102.11.0+build1-0ubuntu0.20.04.1
1:102.13.0+build1-0ubuntu0.20.04.1
1:102.15.0+build1-0ubuntu0.20.04.1
1:102.15.1+build1-0ubuntu0.20.04.1

1:115.*

1:115.3.1+build1-0ubuntu0.20.04.1
1:115.4.1+build1-0ubuntu0.20.04.1
1:115.5.0+build1-0ubuntu0.20.04.1
1:115.6.0+build2-0ubuntu0.20.04.1
1:115.8.1+build1-0ubuntu0.20.04.1
1:115.9.0+build1-0ubuntu0.20.04.1
1:115.10.1+build1-0ubuntu0.20.04.1
1:115.11.0+build2-0ubuntu0.20.04.1
1:115.12.0+build3-0ubuntu0.20.04.1
1:115.13.0+build5-0ubuntu0.20.04.1
1:115.15.0+build1-0ubuntu0.20.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs78

Package

Name
mozjs78
Purl
pkg:deb/ubuntu/mozjs78?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

78.*

78.13.0-1
78.15.0-2
78.15.0-4ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / mozjs91

Package

Name
mozjs91
Purl
pkg:deb/ubuntu/mozjs91?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

91.*

91.5.1-0ubuntu1
91.6.0-1
91.6.0-2
91.7.0-2
91.10.0-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:91.*

1:91.1.2+build1-0ubuntu1
1:91.3.0+build2-0ubuntu1
1:91.3.1+build1-0ubuntu1
1:91.3.2+build1-0ubuntu1
1:91.4.0+build1.1-0ubuntu1
1:91.4.0+build2-0ubuntu1
1:91.5.0+build1-0ubuntu1
1:91.5.1+build1-0ubuntu1
1:91.6.1+build1-0ubuntu1
1:91.7.0+build1-0ubuntu1
1:91.7.0+build2-0ubuntu1
1:91.8.0+build2-0ubuntu1
1:91.9.1+build1-0ubuntu0.22.04.1
1:91.11.0+build2-0ubuntu0.22.04.1

1:102.*

1:102.2.2+build1-0ubuntu0.22.04.1
1:102.4.2+build2-0ubuntu0.22.04.1
1:102.7.1+build2-0ubuntu0.22.04.1
1:102.8.0+build2-0ubuntu0.22.04.1
1:102.9.0+build1-0ubuntu0.22.04.1
1:102.10.0+build2-0ubuntu0.22.04.1
1:102.11.0+build1-0ubuntu0.22.04.1
1:102.13.0+build1-0ubuntu0.22.04.1
1:102.15.0+build1-0ubuntu0.22.04.1
1:102.15.1+build1-0ubuntu0.22.04.1

1:115.*

1:115.3.1+build1-0ubuntu0.22.04.2
1:115.4.1+build1-0ubuntu0.22.04.1
1:115.5.0+build1-0ubuntu0.22.04.1
1:115.6.0+build2-0ubuntu0.22.04.1
1:115.8.1+build1-0ubuntu0.22.04.1
1:115.9.0+build1-0ubuntu0.22.04.1
1:115.10.1+build1-0ubuntu0.22.04.1
1:115.11.0+build2-0ubuntu0.22.04.1
1:115.12.0+build3-0ubuntu0.22.04.1
1:115.13.0+build5-0ubuntu0.22.04.1
1:115.15.0+build1-0ubuntu0.22.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:115.*

1:115.3.1+build1-0ubuntu1
1:115.4.1+build1-0ubuntu1
1:115.4.3+build1-0ubuntu1
1:115.5.0+build1-0ubuntu1
1:115.5.1+build1-0ubuntu1
1:115.5.2+build2-0ubuntu1
1:115.6.0+build1-0ubuntu1
1:115.6.0+build2-0ubuntu1
1:115.6.1+build1-0ubuntu1
1:115.8.0+build1-0ubuntu1
1:115.8.1+build1+snap2
1:115.8.1+build1+snap3

Other

2:1snap1-0ubuntu1
2:1snap1-0ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}