---
title: "CVE-2022-37454"
canonical: "https://kb.cynergy.app/space/MD/1268252678/CVE-2022-37454"
format: markdown
---
**Description**

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

**Published On**

10/21/2022

**Updated On**

01/28/2025

**Trending**

False

**CWE**

NA

**Exploit**

 NA

**Mitigation:**

![image](media://34f6adc8-90b2-4b28-b16c-b7c2a7ad86e2)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Based on the PHP version in use, you are advised to upgrade PHP versions to the below and follow the reference for the specific update based on OS in the references to fix below. 

- Upgrade PHP to -7.4.33
- Upgrade PHP to-8.0.25
- Upgrade PHP to-8.1.12

**References to fix**

[[debian-lts-announce] 20221031 [SECURITY] [DLA 3174-1] pysha3 security update (https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html)](https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html)

[[debian-lts-announce] 20221101 [SECURITY] [DLA 3175-1] python3.7 security update (https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html)](https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html)

[FEDORA-2022-f2a5082860 (https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/)](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/)

[DSA-5267 (https://www.debian.org/security/2022/dsa-5267)](https://www.debian.org/security/2022/dsa-5267)

[DSA-5269 (https://www.debian.org/security/2022/dsa-5269)](https://www.debian.org/security/2022/dsa-5269)

[FEDORA-2022-1ecc10276e (https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/)](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/)

**Additional References**

- [csrc.nist.gov: https://csrc.nist.gov/projects/hash-functions/sha-3-project](https://csrc.nist.gov/projects/hash-functions/sha-3-project)
- [mouha.be: https://mouha.be/sha-3-buffer-overflow/](https://mouha.be/sha-3-buffer-overflow/)
- [news.ycombinator.com: https://news.ycombinator.com/item?id=33281106](https://news.ycombinator.com/item?id=33281106)
- [github.com: https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658](https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658)
- [lists.debian.org: https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html](https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html)
- [lists.debian.org: https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html](https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html)
- [lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/)
- [debian.org: https://www.debian.org/security/2022/dsa-5267](https://www.debian.org/security/2022/dsa-5267)
- [debian.org: https://www.debian.org/security/2022/dsa-5269](https://www.debian.org/security/2022/dsa-5269)
- [lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/)
- [https://eprint.iacr.org/2023/331](https://eprint.iacr.org/2023/331)
- [https://news.ycombinator.com/item?id=35050307](https://news.ycombinator.com/item?id=35050307)
- [https://security.gentoo.org/glsa/202305-02](https://security.gentoo.org/glsa/202305-02)