CVE-2022-1286
published 2022-04-10CVE-2022-1286: heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.11%
62.3th percentile
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mruby | < mruby 3.0.0-4 (bookworm) | mruby 3.0.0-4 (bookworm) |
| juniper | junos_os | — | — |
| mruby | mruby | < 3.2 | 3.2 |
| mruby | mruby | >= 0 < 3.0.0-4 | 3.0.0-4 |
| mruby | mruby | >= 0 < 3.0.0-4 | 3.0.0-4 |
| mruby | mruby | >= 0 < 3.0.0-4 | 3.0.0-4 |
| mruby | mruby_mruby | >= unspecified < 3.2 | 3.2 |
| msrc | azl3_grpc_1.42.0-7 | — | — |
| msrc | azl3_keras_2.11.0-3 | — | — |
| msrc | azl3_keras_3.1.1-1 | — | — |
| msrc | azl3_mozjs_102.15.1-1 | — | — |
| msrc | azl3_mysql_8.0.36-1 | — | — |
| msrc | azl3_mysql_8.0.40-1 | — | — |
| msrc | azl3_protobuf_25.3-1 | — | — |
| msrc | azl3_protobuf_3.17.3-2 | — | — |
| msrc | azl3_python-tensorboard_2.11.0-3 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-1 | — | — |
| msrc | azl3_pytorch_2.2.2-2 | — | — |
| msrc | azl3_pytorch_2.2.2-7 | — | — |
| msrc | azl3_tensorflow_2.11.1-1 | — | — |
| msrc | azl3_tensorflow_2.16.1-1 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_grpc_1.42.0-11 | — | — |
| msrc | cbl2_keras_2.11.0-3 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6c7w-5xfj-j2mc: heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3
ghsa_unreviewed·2022-04-11
CVE-2022-1286 [CRITICAL] CWE-122 GHSA-6c7w-5xfj-j2mc: heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
OSV
CVE-2022-1286: heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3
osv·2022-04-10·CVSS 9.8
CVE-2022-1286 [CRITICAL] CVE-2022-1286: heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Juniper
CVE-2022-22192: An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a netwo
vendor_juniper·2022-10-18·CVSS 7.5
CVE-2022-22192 [HIGH] CWE-1286 CVE-2022-22192: An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a netwo
CVE-2022-22192: An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolved on PTX series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an incoming TCP packet destined to the device is malformed there is a possibility of a kernel panic. Only TCP packets destined to the ports for BGP, LDP and MSDP can trigger this. This issue only affects PTX10004, PTX10008, PTX10016. No other PTX Series devices or other platforms are affected. This issue affects Juniper Networks Junos OS Evolved: 20.4-EVO versions prior to 20.4R3-S4-EVO; 21.3-EVO versions prior to 21.3R3-EVO; 21.4-EVO versions prior to 21.4R3-EVO; 22.1-EVO versions prior to 22.1R2-EVO. This issue does not affect Juniper Networks Junos
Red Hat
protobuf: message parsing vulnerability in ProtocolBuffers
vendor_redhat·2022-09-22·CVSS 7.5
CVE-2022-1941 [HIGH] CWE-1286 protobuf: message parsing vulnerability in ProtocolBuffers
protobuf: message parsing vulnerability in ProtocolBuffers
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.
A parsing vulnerability for the MessageSet type in the ProtocolBuf
Microsoft
Out of Memory issue in ProtocolBuffers for cpp and python
vendor_msrc·2022-09-13·CVSS 7.5
CVE-2022-1941 [HIGH] CWE-1286 Out of Memory issue in ProtocolBuffers for cpp and python
Out of Memory issue in ProtocolBuffers for cpp and python
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://l
Red Hat
curl: Incorrect handling of control code characters in cookies
vendor_redhat·2022-08-31·CVSS 3.7
CVE-2022-35252 [LOW] CWE-1286 curl: Incorrect handling of control code characters in cookies
curl: Incorrect handling of control code characters in cookies
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
A vulnerability found in curl. This security flaw happens when curl is used to retrieve and parse cookies from an HTTP(S) server, where it accepts cookies using control codes (byte values below 32), and also when cookies that contain such control codes are later sent back to an HTTP(S) server, possibly causing the server to return a 400 response. This issue effectively allows a "sister site" to deny service to siblings and cause a denial of service attack.
Packa
Juniper
CVE-2022-22176: An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adja
vendor_juniper·2022-01-19·CVSS 7.4
CVE-2022-22176 [HIGH] CWE-1286 CVE-2022-22176: An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adja
CVE-2022-22176: An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If option-82 is configured in a DHCP snooping / -security scenario, jdhcpd crashes if a specific malformed DHCP request packet is received. The DHCP functionality is impacted while jdhcpd restarts, and continued exploitation of the vulnerability will lead to the unavailability of the DHCP service and thereby a sustained DoS. This issue affects Juniper Networks Junos OS 13.2 version 13.2R1 and later versions prior to 15.1R7-S11; 18.3 versions prior to 18.3R3-S6; 18.4 versions prior to 18.4R2-S9, 18.4R3
Debian
CVE-2022-1286: mruby - heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mr...
vendor_debian·2022·CVSS 9.8
CVE-2022-1286 [CRITICAL] CVE-2022-1286: mruby - heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mr...
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Scope: local
bookworm: resolved (fixed in 3.0.0-4)
bullseye: open
forky: resolved (fixed in 3.0.0-4)
sid: resolved (fixed in 3.0.0-4)
trixie: resolved (fixed in 3.0.0-4)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-10
Published