CVE-2022-48468: Integer Overflow
Published Apr 13, 2023
·Updated
protobuf-c before 1.4.1 has an unsigned integer overflow in parserequiredmember.
Affected Software
4 affected componentsFixes available
Protobuf-c Project Protobuf-c<1.4.1
IBM Business Automation Insights<=25.0.0
IBM Business Automation Insights<=24.0.1
IBM Business Automation Insights<=24.0.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 14, 2023
Data Sourced
via Red Hat·05:43 AM
DescriptionSeverityAffected Software
Nov 3, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48468?
CVE-2022-48468 is classified as having a moderate severity due to the potential for an unsigned integer overflow.
2
How do I fix CVE-2022-48468?
To fix CVE-2022-48468, upgrade to protobuf-c version 1.4.1 or later.
3
Which software is affected by CVE-2022-48468?
CVE-2022-48468 affects protobuf-c versions prior to 1.4.1 as well as specific versions of IBM QRadar SIEM and IBM QRadar Incident Forensics.
4
What type of vulnerability is CVE-2022-48468?
CVE-2022-48468 is an unsigned integer overflow vulnerability.
5
Is CVE-2022-48468 exploitable remotely?
CVE-2022-48468 may be exploitable remotely, depending on how the vulnerable software is integrated and deployed.