---
title: "CVE-2022-38752\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-38752?format=md
keywords: index, follow
---

# CVE-2022-38752

Publication date 5 September 2022

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2022-38752?format=md#impact-score)

Toggle side navigation

## Description

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial
of Service attacks (DOS). If the parser is running on user supplied input,
an attacker may supply content that causes the parser to crash by
stack-overflow.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2022-38752?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| snakeyaml | 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [john-breton](https://launchpad.net/~john-breton)

False positive per upstream. No fix exists or will be
released, untrusted YAML files are not read by snakeYAML.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38752)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-38752)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-38752)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-38752)

### Other references

* <https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081>
* <https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081>
* <https://www.cve.org/CVERecord?id=CVE-2022-38752>
