CVE-2022-3821: Buffer Overflow

Published Nov 2, 2022
·
Updated

An off-by-one Error issue was discovered in Systemd in formattimespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in formattimespan(), leading to a Denial of Service.

Other sources

systemd is vulnerable to a denial of service, caused by an off-by-one error in formattimespan() function of time-util.c. By sending specific values for time and accuracy, a local attacker could exploit this vulnerability to cause a denial of service.

IBM

Systemd: The formattimespan function in time-util.c triggers buffer overrun with crafted time values. Supplying specific values for time and accuracy leads to buffer overrun in formattimespan, leading to Denial of Service.

References: https://github.com/systemd/systemd/issues/23928 https://github.com/systemd/systemd/pull/23933 https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e

Red Hat

Affected Software

12 affected componentsFixes available
redhat/systemd<251
251
redhat/systemd<252
252
IBM Data Virtualization on Cloud Pak for Data<=3.0
IBM Watson Query on Cloud Pak for Data<=2.2
IBM Watson Query on Cloud Pak for Data<=2.1
IBM Watson Query on Cloud Pak for Data<=2.0
IBM Data Virtualization on Cloud Pak for Data<=1.8
IBM Data Virtualization on Cloud Pak for Data<=1.7
Systemd Project Systemd<=251
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Fedoraproject Fedora=35

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/systemd to a version that resolves this vulnerability.

    Fixed in 251
  2. Upgrade

    Upgrade redhat/systemd to a version that resolves this vulnerability.

    Fixed in 252

Event History

Nov 2, 2022
Data Sourced
via Red Hat·07:54 AM
DescriptionSeverityAffected Software
Nov 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 15, 2025
Data Sourced
via IBM·03:29 PM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-3821?

CVE-2022-3821 is an off-by-one Error issue discovered in Systemd in the format_timespan() function of time-util.c.

2

What is the severity of CVE-2022-3821?

The severity of CVE-2022-3821 is medium with a CVSS score of 5.5.

3

How does CVE-2022-3821 affect Systemd?

CVE-2022-3821 affects Systemd versions up to and including 251.

4

How can an attacker exploit CVE-2022-3821?

An attacker can exploit CVE-2022-3821 by supplying specific values for time and accuracy that lead to a buffer overrun in the format_timespan() function, leading to a Denial of Service.

5

Where can I find more information about CVE-2022-3821?

You can find more information about CVE-2022-3821 on the following references: [1] https://bugzilla.redhat.com/show_bug.cgi?id=2139327 [2] https://github.com/systemd/systemd/commit/9102c625a673a3246d7e73d8737f3494446bad4e [3] https://github.com/systemd/systemd/issues/23928

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203