VDB
BDU%3A2022-06445
BDU%3A2022-06445
PUBLISHED
CVSS 10 CRITICAL
Уязвимость криптографической хэш-функции SHA-3 программного пакета eXtended Keccak Code Package (XKCP), позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Red Hat Inc., Сообщество свободного программного обеспечения, Fedora Project, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», PHP Group, АО "НППКТ", Python Software Foundation, АО «НТЦ ИТ РОСА» | Ubuntu, Red Hat Enterprise Linux, Debian GNU/Linux, Red Hat Software Collections, Fedora, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), eXtended Keccak Code Package, PHP, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Python, РОСА ХРОМ (запись в едином реестре российских программ №1607) |
Timeline
- Oct 24, 2022 CVE Published
- Oct 24, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- https://csrc.nist.gov/projects/hash-functions/sha-3-project url
- https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658 url
- https://mouha.be/sha-3-buffer-overflow/ url
- https://news.ycombinator.com/item?id=33281106 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.7/ url
- https://github.com/python/cpython/issues/98517 url
- https://github.com/python/cpython/commit/0e4e058602d93b88256ff90bbef501ba20be9dd3 url
- https://github.com/python/cpython/commit/857efee6d2d43c5c12fc7e377ce437144c728ab8 url
- https://github.com/python/cpython/commit/948c6794711458fd148a3fa62296cadeeb2ed631 url
- https://github.com/python/cpython/commit/8088c90044ba04cd5624b278340ebf934dbee4a5 url
- https://ubuntu.com/security/notices/USN-5717-1 url
- https://ubuntu.com/security/notices/USN-5767-1 url
- https://ubuntu.com/security/notices/USN-5888-1 url
- https://ubuntu.com/security/notices/USN-5767-3 url
- https://ubuntu.com/security/notices/USN-5930-1 url
- https://github.com/php/php-src/commit/91663a92d1697fc30a7ba4687d73e0f63ec2baa1 url
- https://github.com/php/php-src/commit/248f647724e385bfb8d83aa5b5a5ca3c4ee2c7fd url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2023-0316SE47MD url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
…and 11 more