CVE-2022-29369

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-29369
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29369.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-29369
Published
2022-05-12T19:15:49.533Z
Modified
2025-11-14T13:14:16.705371Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njslvlhshbucketfind at njslvlhsh.c.

References

Affected packages

Git / github.com/nginx/njs

Affected ranges

Type
GIT
Repo
https://github.com/nginx/njs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2

Database specific

vanir_signatures

[
    {
        "digest": {
            "line_hashes": [
                "175810938689306307151989758938324830392",
                "180703331715133232550731353903580460069",
                "257687700515119752060853364737589949899",
                "201715238112720295438944879166792311002",
                "86923884048140837451821738852591075233",
                "151539192229205972088332502047357359123",
                "320979593805069523545407758307501457704",
                "251462602731947865340571933625060618058",
                "141237680761797995961273377335536878984",
                "215895325570199931832640693944774457452",
                "51559773004152251879208073319942502774",
                "143231716330137716612267197204713042554",
                "172795507435902619979286648356063634762",
                "290427967150929695050296094226983982013",
                "105803064134099642247227259911095218386",
                "233295550805243044926178074394196479305",
                "119734970276082523690767603892505989894",
                "290427967150929695050296094226983982013",
                "98385400436157425460867402775036451519",
                "5168429043744573656665556283788086544"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "signature_version": "v1",
        "id": "CVE-2022-29369-89956614",
        "target": {
            "file": "src/njs_vmcode.c"
        },
        "source": "https://github.com/nginx/njs/commit/222d6fdcf0c6485ec8e175f3a7b70d650c234b4e"
    },
    {
        "digest": {
            "function_hash": "240803892515240890895402971671006348816",
            "length": 16617.0
        },
        "signature_type": "Function",
        "deprecated": false,
        "signature_version": "v1",
        "id": "CVE-2022-29369-b32f9508",
        "target": {
            "file": "src/njs_vmcode.c",
            "function": "njs_vmcode_interpreter"
        },
        "source": "https://github.com/nginx/njs/commit/222d6fdcf0c6485ec8e175f3a7b70d650c234b4e"
    },
    {
        "digest": {
            "line_hashes": [
                "133478195713163801148079192355661780482",
                "320995026320866511970333713561071258808",
                "89133782025725445036970021207302582100"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "deprecated": false,
        "signature_version": "v1",
        "id": "CVE-2022-29369-bb03f80d",
        "target": {
            "file": "src/test/njs_unit_test.c"
        },
        "source": "https://github.com/nginx/njs/commit/222d6fdcf0c6485ec8e175f3a7b70d650c234b4e"
    }
]