CVE-2022-1240
published 2022-04-06CVE-2022-1240: Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.73%
49.9th percentile
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.9.0+dfsg-1 (sid) | radare2 5.9.0+dfsg-1 (sid) |
| radare | radare2 | <= 5.6.6 | — |
| radareorg | radareorg_radare2 | >= unspecified < 5.8.6 | 5.8.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m6g3-mrp2-c625: Heap buffer overflow in libr/bin/format/mach0/mach0
ghsa_unreviewed·2022-04-07
CVE-2022-1240 [HIGH] CWE-122 GHSA-m6g3-mrp2-c625: Heap buffer overflow in libr/bin/format/mach0/mach0
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).
OSV
CVE-2022-1240: Heap buffer overflow in libr/bin/format/mach0/mach0
osv·2022-04-06·CVSS 7.8
CVE-2022-1240 [HIGH] CVE-2022-1240: Heap buffer overflow in libr/bin/format/mach0/mach0
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).
Red Hat
hw: cpu: cryptographic leaks via frequency scaling attacks(Intel)
vendor_redhat·2022-06-14·CVSS 6.5
CVE-2022-24436 [MEDIUM] CWE-1240 hw: cpu: cryptographic leaks via frequency scaling attacks(Intel)
hw: cpu: cryptographic leaks via frequency scaling attacks(Intel)
Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access.
A potential vulnerability in some Intel® processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
Mitigation: Currently, there is no mitigation for this flaw. Intel has provided some guidance to developers of Cryptographic software to harden their libraries and applications against Hertzbleed. More information is available in the official Intel and AMD security advisories linked at the bottom of this document.
A workload-independent workaround to mitigate Hertz
Red Hat
hw: cpu: cryptographic leaks via frequency scaling attacks(AMD)
vendor_redhat·2022-06-14·CVSS 6.5
CVE-2022-23823 [MEDIUM] CWE-1240 hw: cpu: cryptographic leaks via frequency scaling attacks(AMD)
hw: cpu: cryptographic leaks via frequency scaling attacks(AMD)
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
Mitigation: For mitigations please refer to the AMD Security Bulletin at https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1038
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2022-1240: radare2 - Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radar...
vendor_debian·2022·CVSS 7.8
CVE-2022-1240 [HIGH] CVE-2022-1240: radare2 - Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radar...
Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-06
Published