Bug 1206471 (CVE-2022-23526) - VUL-0: CVE-2022-23526: helm,helm3: Denial of service through schema file
Summary: VUL-0: CVE-2022-23526: helm,helm3: Denial of service through schema file
Status: RESOLVED FIXED
Alias: CVE-2022-23526
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/350921/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-23526:3.7:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2022-12-16 09:28 UTC by Cathy Hu
Modified: 2024-05-03 09:34 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2022-12-16 09:28:01 UTC
CVE-2022-23526

Helm is a tool for managing Charts, pre-configured Kubernetes resources.
Versions prior to 3.10.3 are subject to NULL Pointer Dereference in
the_chartutil_ package that can cause a segmentation violation. The _chartutil_
package contains a parser that loads a JSON Schema validation file. For example,
the Helm client when rendering a chart will validate its values with the schema
file. The _chartutil_ package parses the schema file and loads it into
structures Go can work with. Some schema files can cause array data structures
to be created causing a memory violation. Applications that use the _chartutil_
package in the Helm SDK to parse a schema file can suffer a Denial of Service
when that input causes a panic that cannot be recovered from. Helm is not a long
running service so the panic will not affect future uses of the Helm client.
This issue has been patched in 3.10.3. SDK users can validate schema files that
are correctly formatted before passing them to the _chartutil_ functions.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-23526
https://github.com/helm/helm/commit/bafafa8bb1b571b61d7a9528da8d40c307dade3d
https://www.cve.org/CVERecord?id=CVE-2022-23526
https://github.com/helm/helm/security/advisories/GHSA-67fx-wx78-jx33
Comment 1 Cathy Hu 2022-12-16 09:28:24 UTC
Affected:
- SUSE:SLE-15-SP1:Update:Products:CASP40:Update/helm   2.16.12
- SUSE:SLE-15-SP1:Update:Products:CASP40:Update/helm3  3.3.3  
- SUSE:SLE-15:Update/helm                              3.9.4  
- openSUSE:Backports:SLE-15-SP3/helm                   3.5.2  
- openSUSE:Backports:SLE-15-SP4/helm                   3.8.0  

Not Affected:
- openSUSE:Factory/helm                                3.10.3
Comment 3 Dirk Mueller 2022-12-16 09:49:58 UTC
SUSE:SLE-15:Update submitted. Reassign to Frederic for coldpool / helm3
Comment 4 OBSbugzilla Bot 2022-12-16 10:25:06 UTC
This is an autogenerated message for OBS integration:
This bug (1206471) was mentioned in
https://build.opensuse.org/request/show/1043303 Factory / helm
Comment 6 Swamp Workflow Management 2022-12-22 14:20:35 UTC
SUSE-SU-2022:4606-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1181419,1206467,1206469,1206471
CVE References: CVE-2021-21272,CVE-2022-1996,CVE-2022-23524,CVE-2022-23525,CVE-2022-23526
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    helm-3.10.3-150000.1.13.1
openSUSE Leap 15.3 (src):    helm-3.10.3-150000.1.13.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    helm-3.10.3-150000.1.13.1
SUSE Linux Enterprise Module for Containers 15-SP4 (src):    helm-3.10.3-150000.1.13.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Cathy Hu 2023-01-05 08:35:18 UTC
Hi Frederic, any updates here? Thanks :)
Comment 9 OBSbugzilla Bot 2023-02-21 11:25:14 UTC
This is an autogenerated message for OBS integration:
This bug (1206471) was mentioned in
https://build.opensuse.org/request/show/1066971 Backports:SLE-15-SP4 / helm
Comment 17 Petr Gajdos 2023-12-18 11:01:31 UTC
Will submit for SUSE:SLE-15-SP1:Update:Products:CASP40:Update/helm3.

I believe all fixed from coldpool side.
Comment 19 Maintenance Automation 2024-01-08 20:30:08 UTC
SUSE-SU-2024:0056-1: An update that solves one vulnerability can now be installed.

Category: security (low)
Bug References: 1206471
CVE References: CVE-2022-23526
Sources used:
SUSE CaaS Platform 4.0 (src): helm3-3.3.3-150100.1.15.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Robert Frohl 2024-05-03 09:34:03 UTC
done, closing