CVE-2022-26083

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2022-26083 NameCVE-2022-26083 DescriptionGeneration of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues,…

CVE-2022-26083

NameCVE-2022-26083
DescriptionGeneration of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ipp-crypto (PTS)trixie2021.12.1-1fixed
forky, sid1:2.2.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ipp-cryptosource(unstable)(not affected)

Notes

- ipp-crypto <not-affected> (Fixed before initial upload to Debian)
https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00667.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- ipp-crypto <not-affected> (Fixed before initial upload to Debian)https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00667.html

OS impact

debian Debian Fixed 3 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.