peter bassill · operator
$ cve CVE-2022-37454 JSON

CVE-2022-37454

9.8
CRITICAL · CVSS 3.1 · EPSS 5.8% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.77% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2022-10-21
Last modified2026-06-17

Affected (8)

VendorProduct
debiandebian linux
extended keccak code package projectextended keccak code package
fedoraprojectfedora
phpphp
pypypypy
pysha3 projectpysha3
pythonpython
sha3 projectsha3

References

→ the Explorer  ·  watch your stack  ·  NVD