CVE-2022-38013
Description
Moderate: .NET 6.0 security and bugfix update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2022-6521.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2022-6539.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2022:6539
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2022-6523.html
Vendor advisory: alma — https://bugzilla.redhat.com/2125124
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2022:6523
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2022:6523
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2022:6539
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-38013
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2022:6521
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
| fedora | 35 | affected | |
| fedora | 36 | affected | |
| fedora | 37 | affected | |
Package impact
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | .net | 6.0.0 | |
| microsoft | .net_core | 3.1 | |
| microsoft | visual_studio_2019 | 16.9 | |
| microsoft | visual_studio_2019 | 16.11 | |
| microsoft | visual_studio_2022 | 17.0 | |
| microsoft | visual_studio_2022 | 17.2 | |
| microsoft | visual_studio_2022 | 17.3 | |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38013
- https://access.redhat.com/errata/RHSA-2022:6521
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2CUL3Z7MEED7RFQZVGQL2MTKSFFZKAAY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HCV4TQGOTOFHO5ETRKGFKAGYV2YAUVE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JA6F4CDKLI3MALV6UK3P2DR5AGCLTT7Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4K5YL7USOKIR3O2DUKBZMYPWXYPDKXG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WL334CKOHA6BQQSYJW365HIWJ4IOE45M/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-38013
- https://errata.rockylinux.org/RLSA-2022:6539
- https://errata.rockylinux.org/RLSA-2022:6523
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-r8m2-4x37-6592
- https://nvd.nist.gov/vuln/detail/CVE-2022-38013
- https://github.com/dotnet/aspnetcore
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2CUL3Z7MEED7RFQZVGQL2MTKSFFZKAAY
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7HCV4TQGOTOFHO5ETRKGFKAGYV2YAUVE
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JA6F4CDKLI3MALV6UK3P2DR5AGCLTT7Y
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K4K5YL7USOKIR3O2DUKBZMYPWXYPDKXG
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WL334CKOHA6BQQSYJW365HIWJ4IOE45M
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2CUL3Z7MEED7RFQZVGQL2MTKSFFZKAAY
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7HCV4TQGOTOFHO5ETRKGFKAGYV2YAUVE
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JA6F4CDKLI3MALV6UK3P2DR5AGCLTT7Y
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K4K5YL7USOKIR3O2DUKBZMYPWXYPDKXG
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WL334CKOHA6BQQSYJW365HIWJ4IOE45M
- https://access.redhat.com/errata/RHSA-2022:6523
- https://bugzilla.redhat.com/2125124
CWEs
CWE-400
Verify integrity in audit chain (admin only). AS-IS.