{"id":"CVE-2022-43507","details":"Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.","modified":"2026-08-27T08:39:37.632603Z","published":"2023-05-10T14:15:24.400Z","related":["SUSE-SU-2023:3290-1"],"references":[{"type":"ADVISORY","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00798.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/intel/QAT_Engine","events":[{"introduced":"0"},{"fixed":"1c95fd724e0b92f9e9b210db64d7cc19469f1977"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.6.16"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:intel:quickassist_technology_engine:*:*:*:*:*:*:*:*"}}],"versions":["v0.6.15","v0.6.14","v0.6.13","v0.6.12","v0.6.11","v0.6.10","v0.6.9","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.5.46","v0.5.45","v0.5.44","v0.5.43","v0.5.42","v0.5.41","v0.5.40","v0.5.39","v0.5.38","v0.5.37","v0.5.36","v0.5.35","v0.5.34","v0.5.33","v0.5.32","v0.5.31","v0.5.30","v0.5.29","v0.5.28","v0.5.27","v0.5.26","v0.5.25","v0.5.24","v0.5.23","v0.5.22","v0.5.21","v0.5.20","v0.5.19","v0.5.18","v0.5.17","v0.5.16","v0.5.15","v0.5.14","v0.5.13","v0.5.12","v0.5.11","v0.5.10","v0.5.9","v0.5.8","v0.5.7","v0.5.6","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43507.json","vanir_signatures_modified":"2026-08-27T08:39:37Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["270858869348280585648282979919579038338","119915446071434239525493028303171176445","107564049208525931793274974442155005968","277365158538378222374458096953232194096","78441572593013828644712200606331984101"]},"id":"CVE-2022-43507-c899954e","signature_type":"Line","signature_version":"v1","source":"https://github.com/intel/QAT_Engine/commit/1c95fd724e0b92f9e9b210db64d7cc19469f1977","target":{"file":"qat_provider.h"}},{"digest":{"line_hashes":["156025310930304741110189901600307719992","173845976601447089807024810858292505512","299562738511750442871730940615843940953","179453621182462454234455446159381659246","235522609912799947819646102083601092484","167502685527457405980628889773506766009","173254830301464810348192717058539871","115977538961557300197374275310826615523","145305443624317969461370421360215952251","301324652803090861127289442785407937691"],"threshold":0.9},"id":"CVE-2022-43507-fada7d2f","signature_type":"Line","signature_version":"v1","source":"https://github.com/intel/QAT_Engine/commit/1c95fd724e0b92f9e9b210db64d7cc19469f1977","target":{"file":"e_qat.c"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/intel/qat_engine","events":[{"introduced":"0"},{"fixed":"1c95fd724e0b92f9e9b210db64d7cc19469f1977"}],"database_specific":{"cpe":"cpe:2.3:a:intel:quickassist_technology_engine:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.6.16"}],"source":"CPE_RANGE"}}],"versions":["v0.6.15","v0.6.14","v0.6.13","v0.6.12","v0.6.11","v0.6.10","v0.6.9","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.5.46","v0.5.45","v0.5.44","v0.5.43","v0.5.42","v0.5.41","v0.5.40","v0.5.39","v0.5.38","v0.5.37","v0.5.36","v0.5.35","v0.5.34","v0.5.33","v0.5.32","v0.5.31","v0.5.30","v0.5.29","v0.5.28","v0.5.27","v0.5.26","v0.5.25","v0.5.24","v0.5.23","v0.5.22","v0.5.21","v0.5.20","v0.5.19","v0.5.18","v0.5.17","v0.5.16","v0.5.15","v0.5.14","v0.5.13","v0.5.12","v0.5.11","v0.5.10","v0.5.9","v0.5.8","v0.5.7","v0.5.6","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43507.json","vanir_signatures_modified":"2026-08-27T08:39:37Z","vanir_signatures":[{"id":"CVE-2022-43507-9cce42e5","signature_type":"Line","signature_version":"v1","source":"https://github.com/intel/qat_engine/commit/1c95fd724e0b92f9e9b210db64d7cc19469f1977","target":{"file":"qat_provider.h"},"deprecated":false,"digest":{"line_hashes":["270858869348280585648282979919579038338","119915446071434239525493028303171176445","107564049208525931793274974442155005968","277365158538378222374458096953232194096","78441572593013828644712200606331984101"],"threshold":0.9}},{"deprecated":false,"digest":{"line_hashes":["156025310930304741110189901600307719992","173845976601447089807024810858292505512","299562738511750442871730940615843940953","179453621182462454234455446159381659246","235522609912799947819646102083601092484","167502685527457405980628889773506766009","173254830301464810348192717058539871","115977538961557300197374275310826615523","145305443624317969461370421360215952251","301324652803090861127289442785407937691"],"threshold":0.9},"id":"CVE-2022-43507-cedab2d2","signature_type":"Line","signature_version":"v1","source":"https://github.com/intel/qat_engine/commit/1c95fd724e0b92f9e9b210db64d7cc19469f1977","target":{"file":"e_qat.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}