CVE-2022-1437

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-1437
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1437.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-1437
Downstream
Related
Published
2022-04-22T14:00:15Z
Modified
2025-11-17T06:55:48.866058Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Heap-based Buffer Overflow in radareorg/radare2
Details

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

Database specific
{
    "cwe_ids": [
        "CWE-122"
    ]
}
References

Affected packages

Git / github.com/radare/radare2

Affected ranges

Type
GIT
Repo
https://github.com/radare/radare2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.4-termux4
0.10.5
0.10.6
0.8.6
0.8.8
0.9
0.9.2
0.9.4
0.9.6
0.9.7
0.9.8
0.9.8-rc1
0.9.8-rc2
0.9.8-rc3
0.9.8-rc4
0.9.9

1.*

1.0
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.2.0-git
1.3.0
1.3.0-git
1.4.0
1.5.0
1.6.0

2.*

2.0.0
2.0.1
2.1.0
2.2.0
2.4.0
2.5.0
2.6.0
2.6.9
2.7.0
2.8.0
2.9.0

3.*

3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.5.1
3.6.0
3.7.0
3.7.1
3.8.0
3.9.0

4.*

4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.1

5.*

5.0.0
5.1.0
5.1.1
5.2.0
5.2.1
5.3.0
5.3.1
5.4.0
5.4.0-git
5.4.2
5.5.0
5.5.2
5.5.4
5.6.0
5.6.2
5.6.4
5.6.6
5.6.8

Other

Continuous-Windows
continuous
radare2-windows-nightly
termux
wip

release-5.*

release-5.0.0

Git / github.com/radareorg/radare2

Affected ranges

Type
GIT
Repo
https://github.com/radareorg/radare2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.4-termux4
0.10.5
0.10.6
0.8.6
0.8.8
0.9
0.9.2
0.9.4
0.9.6
0.9.7
0.9.8
0.9.8-rc1
0.9.8-rc2
0.9.8-rc3
0.9.8-rc4
0.9.9

1.*

1.0
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.2.0-git
1.3.0
1.3.0-git
1.4.0
1.5.0
1.6.0

2.*

2.0.0
2.0.1
2.1.0
2.2.0
2.4.0
2.5.0
2.6.0
2.6.9
2.7.0
2.8.0
2.9.0

3.*

3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.5.1
3.6.0
3.7.0
3.7.1
3.8.0
3.9.0

4.*

4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.1

5.*

5.0.0
5.1.0
5.1.1
5.2.0
5.2.1
5.3.0
5.3.1
5.4.0
5.4.0-git
5.4.2
5.5.0
5.5.2
5.5.4
5.6.0
5.6.2
5.6.4
5.6.6
5.6.8

Other

Continuous-Windows
continuous
radare2-windows-nightly
termux

release-5.*

release-5.0.0

Database specific

vanir_signatures

[
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "id": "CVE-2022-1437-33391a5e",
        "digest": {
            "line_hashes": [
                "138693604495067411794579853648689040276",
                "192389519543860150822287882870339407090",
                "200165034670220026660706949201697241326",
                "90944351391191880315126078704013152583",
                "335379302207309119940498399793302688204",
                "9222836352736577291301015831593666256",
                "76143758917753724437476448419065014866",
                "90045214633543585341655389710687243301",
                "46214539267205097658728813314056158417",
                "74284135167786554200251777578716366971",
                "71427958366594747736701486125760737737",
                "149222377276994293819104606140935440476",
                "213599378387971688832358308688412649264",
                "251438527729977619323233238274779914508",
                "99065664217352076992758943532210083317",
                "49845284922868241535700316265584361436",
                "52122206415299668117714924310089338685",
                "328405523240837624891892705044908461330",
                "328517532320645265061621326912521277018",
                "144104320200416567339374915915317262215",
                "302431278455242844457399251083515005303",
                "330518452357161222762211549395545356118",
                "140679971906578263230046294230922605402",
                "281624004686601620991167109092095539275",
                "83387606966192211863881531258531792329"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/radareorg/radare2/commit/669a404b6d98d5db409a5ebadae4e94b34ef5136",
        "deprecated": false,
        "target": {
            "file": "libr/bin/p/bin_symbols.c"
        }
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "id": "CVE-2022-1437-5d6270b5",
        "digest": {
            "length": 940.0,
            "function_hash": "9420094289079351282359704340578115575"
        },
        "source": "https://github.com/radareorg/radare2/commit/669a404b6d98d5db409a5ebadae4e94b34ef5136",
        "deprecated": false,
        "target": {
            "function": "symbols",
            "file": "libr/bin/p/bin_symbols.c"
        }
    },
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "id": "CVE-2022-1437-8ff2f6ad",
        "digest": {
            "line_hashes": [
                "70055843115060226660579789150443220896",
                "112538013887134762811866918635588704219",
                "305068674458780711506558287662610636909",
                "289475696544013406029637457709381946204",
                "109872345890548507111043793516829325255",
                "7769317694280190954251375853474176918",
                "307306013130289992590572818902219614863",
                "295499223733483688836331676204809090457"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/radareorg/radare2/commit/669a404b6d98d5db409a5ebadae4e94b34ef5136",
        "deprecated": false,
        "target": {
            "file": "libr/bin/format/mach0/coresymbolication.c"
        }
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "id": "CVE-2022-1437-a5c2a212",
        "digest": {
            "length": 6803.0,
            "function_hash": "164792329062977318754675288281492114269"
        },
        "source": "https://github.com/radareorg/radare2/commit/669a404b6d98d5db409a5ebadae4e94b34ef5136",
        "deprecated": false,
        "target": {
            "function": "r_coresym_cache_element_new",
            "file": "libr/bin/format/mach0/coresymbolication.c"
        }
    }
]