CVE-2022-37454 is a critical integer overflow and resultant buffer overflow vulnerability in the Keccak XKCP SHA-3 reference implementation, affecting products such as Debian, Fedora, PHP, Python, and PyPy. This flaw, residing in the sponge function interface, allows unauthenticated remote attackers to execute arbitrary code or compromise cryptographic properties. With a CVSS score of 9.8 (CRITICAL), it presents a high-impact threat due to its network-based attack vector and low complexity. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media attention, indicating a recognized risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:extended_keccak_code_package_project:extended_keccak_code_package:-:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Buffer overflow in sponge queue functions
Apr 26, 2023CVE-2022-37454
Nov 8, 2022XKCP: buffer overflow in the SHA-3 reference implementation
Oct 20, 2022The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Oct 11, 2022