{"id":"CVE-2022-2526","details":"A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.","modified":"2026-08-12T13:00:17.262156Z","published":"2022-09-09T00:00:00Z","related":["ALSA-2022:6206"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2526.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2526.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2526"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20221111-0005/"},{"type":"FIX","url":"https://github.com/systemd/systemd/commit/d973d94dec349fb676fdd844f6fe2ada3538f27c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/systemd/systemd","events":[{"introduced":"1742aae2aa8cd33897250d6fcfbe10928e43eb2f"},{"fixed":"d973d94dec349fb676fdd844f6fe2ada3538f27c"}],"database_specific":{"extracted_events":[{"introduced":"240"},{"last_affected":"240"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:systemd_project:systemd:240:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/systemd/systemd-stable","events":[{"introduced":"1742aae2aa8cd33897250d6fcfbe10928e43eb2f"},{"last_affected":"1742aae2aa8cd33897250d6fcfbe10928e43eb2f"}],"database_specific":{"cpe":"cpe:2.3:a:systemd_project:systemd:240:*:*:*:*:*:*:*","extracted_events":[{"introduced":"240"},{"last_affected":"240"}],"source":"CPE_STRING"}}],"versions":["240","systemd 240","v240"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2526.json","vanir_signatures_modified":"2026-08-12T13:00:17Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"208401693791038653337512553355040068330","length":4329},"id":"CVE-2022-2526-0518585b","signature_type":"Function","signature_version":"v1","source":"https://github.com/systemd/systemd/commit/d973d94dec349fb676fdd844f6fe2ada3538f27c","target":{"file":"src/resolve/resolved-dns-stream.c","function":"on_stream_io"}},{"id":"CVE-2022-2526-3d277f7d","signature_type":"Function","signature_version":"v1","source":"https://github.com/systemd/systemd/commit/d973d94dec349fb676fdd844f6fe2ada3538f27c","target":{"function":"dns_stream_complete","file":"src/resolve/resolved-dns-stream.c"},"deprecated":false,"digest":{"function_hash":"165753356205743956457529010201804762870","length":358}},{"source":"https://github.com/systemd/systemd/commit/d973d94dec349fb676fdd844f6fe2ada3538f27c","target":{"file":"src/resolve/resolved-dns-stream.c"},"deprecated":false,"digest":{"line_hashes":["24244502987640347669429748297519997487","305861172124080797233263628752068476767","201898119636995375130900012674839025850","243976609872396757423323106453765157402","25033070272748089651412234795692720617","4749797598595707144303836668512376180","102934075727237860555720616686638501394","89242042041014859283960974229838224291"],"threshold":0.9},"id":"CVE-2022-2526-7591cea9","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0"}