{
    "id": "CVE-2022-37454",
    "published": "2022-10-21 06:15:09",
    "last_modified": "2026-06-17 04:55:07",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-190",
    "description": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.",
    "epss_score": "0.05765",
    "epss_percentile": "0.92871",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-06 18:17:30",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "extended_keccak_code_package_project",
            "product": "extended_keccak_code_package"
        },
        {
            "vendor": "fedoraproject",
            "product": "fedora"
        },
        {
            "vendor": "php",
            "product": "php"
        },
        {
            "vendor": "pypy",
            "product": "pypy"
        },
        {
            "vendor": "pysha3_project",
            "product": "pysha3"
        },
        {
            "vendor": "python",
            "product": "python"
        },
        {
            "vendor": "sha3_project",
            "product": "sha3"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
        "https://eprint.iacr.org/2023/331",
        "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
        "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
        "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
        "https://mouha.be/sha-3-buffer-overflow/",
        "https://news.ycombinator.com/item?id=33281106",
        "https://news.ycombinator.com/item?id=35050307",
        "https://security.gentoo.org/glsa/202305-02",
        "https://www.debian.org/security/2022/dsa-5267",
        "https://www.debian.org/security/2022/dsa-5269",
        "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
        "https://eprint.iacr.org/2023/331",
        "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
        "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
        "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
        "https://mouha.be/sha-3-buffer-overflow/",
        "https://news.ycombinator.com/item?id=33281106",
        "https://news.ycombinator.com/item?id=35050307",
        "https://security.gentoo.org/glsa/202305-02",
        "https://security.netapp.com/advisory/ntap-20230203-0001/"
    ]
}