CVE-2022-1899

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-1899
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1899.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-1899
Downstream
Related
Published
2022-05-26T17:15:08Z
Modified
2025-10-25T12:13:36.177837Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

References

Affected packages

Git / github.com/radare/radare2

Affected ranges

Type
GIT
Repo
https://github.com/radare/radare2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.4-termux4
0.10.5
0.10.6
0.8.6
0.8.8
0.9
0.9.2
0.9.4
0.9.6
0.9.7
0.9.8
0.9.8-rc1
0.9.8-rc2
0.9.8-rc3
0.9.8-rc4
0.9.9

1.*

1.0
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.2.0-git
1.3.0
1.3.0-git
1.4.0
1.5.0
1.6.0

2.*

2.0.0
2.0.1
2.1.0
2.2.0
2.4.0
2.5.0
2.6.0
2.6.9
2.7.0
2.8.0
2.9.0

3.*

3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.5.1
3.6.0
3.7.0
3.7.1
3.8.0
3.9.0

4.*

4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.1

5.*

5.0.0
5.1.0
5.1.1
5.2.0
5.2.1
5.3.0
5.3.1
5.4.0
5.4.0-git
5.4.2
5.5.0
5.5.2
5.5.4
5.6.0
5.6.2
5.6.4
5.6.6
5.6.8

Other

Continuous-Windows
continuous
radare2-windows-nightly
termux
wip

release-5.*

release-5.0.0

Git / github.com/radareorg/radare2

Affected ranges

Type
GIT
Repo
https://github.com/radareorg/radare2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.4-termux4
0.10.5
0.10.6
0.8.6
0.8.8
0.9
0.9.2
0.9.4
0.9.6
0.9.7
0.9.8
0.9.8-rc1
0.9.8-rc2
0.9.8-rc3
0.9.8-rc4
0.9.9

1.*

1.0
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.2.0-git
1.3.0
1.3.0-git
1.4.0
1.5.0
1.6.0

2.*

2.0.0
2.0.1
2.1.0
2.2.0
2.4.0
2.5.0
2.6.0
2.6.9
2.7.0
2.8.0
2.9.0

3.*

3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
3.1.3
3.2.0
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.5.1
3.6.0
3.7.0
3.7.1
3.8.0
3.9.0

4.*

4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0
4.5.1

5.*

5.0.0
5.1.0
5.1.1
5.2.0
5.2.1
5.3.0
5.3.1
5.4.0
5.4.0-git
5.4.2
5.5.0
5.5.2
5.5.4
5.6.0
5.6.2
5.6.4
5.6.6
5.6.8

Other

Continuous-Windows
continuous
radare2-windows-nightly
termux
wip

release-5.*

release-5.0.0

Database specific

vanir_signatures

[
    {
        "source": "https://github.com/radareorg/radare2/commit/193f4fe01d7f626e2ea937450f2e0c4604420e9d",
        "target": {
            "file": "libr/bin/bfile.c",
            "function": "string_scan_range"
        },
        "id": "CVE-2022-1899-5f9b1488",
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "228971568819817510516129273139297019081",
            "length": 6355.0
        },
        "deprecated": false
    },
    {
        "source": "https://github.com/radareorg/radare2/commit/193f4fe01d7f626e2ea937450f2e0c4604420e9d",
        "target": {
            "file": "libr/bin/bfile.c"
        },
        "id": "CVE-2022-1899-aaa5b96b",
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "316211719619962917818214520025320785140",
                "287363439218873049190429947570261455472",
                "195900945464636424928724027390037748908",
                "95191900171587528788222985677711536947",
                "273884518050101248296644942716537985298",
                "315293584955577210699405466004311776744",
                "145098661352195905512076391511372307731",
                "238331328460380917371913987547583510324",
                "198874052047521997588881171144500392582",
                "9776123745438980096169944960489772783",
                "77326840629232461638261767379315583547",
                "223825157817358627905152752101815789401",
                "214076863284999387358063492351247276455",
                "289132356716171667647408942755565402781",
                "170250615419712487199310085690756157917",
                "243408949340784804397882497752649499690",
                "330510162229162179022683726297306067943",
                "124295829070715876540208700103971270205",
                "62189560450093041246917983728225357377",
                "270553255666369254564466808791963875520",
                "271773453403532209692308711336042833815",
                "300223334043054578548074435297574570409",
                "49580179729391202647316088051673296973"
            ]
        },
        "deprecated": false
    }
]