CVE-2022-1207
published 2022-04-01CVE-2022-1207: Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the…
PriorityP424medium6.6CVSS 3.1
AVLACLPRNUIRSUCHILAL
EPSS
0.91%
55.9th percentile
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.9.0+dfsg-1 (sid) | radare2 5.9.0+dfsg-1 (sid) |
| radare | radare2 | < 5.6.8 | 5.6.8 |
| radareorg | radareorg_radare2 | >= unspecified < 5.6.8 | 5.6.8 |
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
nvdv3.06.6MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: XArray: Fix xas_create_range() when multi-order entry present
vendor_redhat·2025-02-26·CVSS 4.7
CVE-2022-49152 [MEDIUM] CWE-476 kernel: XArray: Fix xas_create_range() when multi-order entry present
kernel: XArray: Fix xas_create_range() when multi-order entry present
In the Linux kernel, the following vulnerability has been resolved:
XArray: Fix xas_create_range() when multi-order entry present
If there is already an entry present that is of order >= XA_CHUNK_SHIFT
when we call xas_create_range(), xas_create_range() will misinterpret
that entry as a node and dereference xa_node->parent, generally leading
to a crash that looks something like this:
general protection fault, probably for non-canonical address 0xdffffc0000000001:
0000 [#1] PREEMPT SMP KASAN
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
CPU: 0 PID: 32 Comm: khugepaged Not tainted 5.17.0-rc8-syzkaller-00003-g56e337f2cf13 #0
RIP: 0010:xa_parent_locked include/linux/xarray.h:1207 [inline]
RIP: 0010:
Debian
CVE-2022-1207: radare2 - Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This v...
vendor_debian·2022·CVSS 6.6
CVE-2022-1207 [MEDIUM] CVE-2022-1207: radare2 - Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This v...
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
GHSA
GHSA-66gq-3g6r-6hjw: Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5
ghsa_unreviewed·2022-04-02
CVE-2022-1207 [MEDIUM] CWE-125 GHSA-66gq-3g6r-6hjw: Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.
OSV
CVE-2022-1207: Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5
osv·2022-04-01·CVSS 6.6
CVE-2022-1207 [MEDIUM] CVE-2022-1207: Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5
Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.
No detection rules found.
No public exploits indexed.
2022-04-01
Published