CVE-2022-1638
published 2022-07-26CVE-2022-1638: Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.69%
49.0th percentile
Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 101.0.4951.64-1~deb11u1 | 101.0.4951.64-1~deb11u1 |
| chromium | chromium | >= 0 < 101.0.4951.64-1 | 101.0.4951.64-1 |
| chromium | chromium | >= 0 < 101.0.4951.64-1 | 101.0.4951.64-1 |
| chromium | chromium | >= 0 < 101.0.4951.64-1 | 101.0.4951.64-1 |
| debian | chromium | < chromium 101.0.4951.64-1 (bookworm) | chromium 101.0.4951.64-1 (bookworm) |
| chrome | < 101.0.4951.64 | 101.0.4951.64 | |
| chrome | >= unspecified < 101.0.4951.64 | 101.0.4951.64 | |
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 5.15.0 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 6.1.0 < 6.1.2 | 6.1.2 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
vendor_redhat·2025-12-08
CVE-2022-50620 kernel: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
kernel: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
Syzbot reports a NULL pointer dereference issue as below:
__refcount_add include/linux/refcount.h:193 [inline]
__refcount_inc include/linux/refcount.h:250 [inline]
refcount_inc include/linux/refcount.h:267 [inline]
get_task_struct include/linux/sched/task.h:110 [inline]
kthread_stop+0x34/0x1c0 kernel/kthread.c:703
f2fs_stop_discard_thread+0x3c/0x5c fs/f2fs/segment.c:1638
kill_f2fs_super+0x5c/0x194 fs/f2fs/super.c:4522
deactivate_locked_super+0x70/0xe8 fs/super.c:332
deactivate_super+0xd0/0xd4 fs/super.c:363
cleanup_mnt+0x1f8/0x234 fs/namespace.c:1186
__cleanup_mnt+0x20/0x30 fs/namespace.c:119
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-1638
vendor_chrome·2022-05-31·CVSS 8.8
CVE-2022-1638 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-1638
Long Term Support Channel Update for ChromeOS
CVE-2022-1638: Heap buffer overflow in V8 Internationalization. 1316990 High CVE-2022-1633: Use after free in Sharesheet
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2022-1636
vendor_chrome·2022-05-10·CVSS 8.8
CVE-2022-1636 [HIGH] Stable Channel Update for Desktop: CVE-2022-1636
Stable Channel Update for Desktop
CVE-2022-1636: Use after free in Performance APIs. Reported by Seth Brenith, Microsoft on 2022-02-15 [$TBD][ 1311820 ] High CVE-2022-1637: Inappropriate implementation in Web Contents
Reported by Alesandro Ortiz on 2022-03-31 [$TBD][ 1316946 ] High CVE-2022-1638: Heap buffer overflow in V8 Internationalization
Severity: high
Microsoft
Chromium: CVE-2022-1638 Heap buffer overflow in V8 Internationalization
vendor_msrc·2022-05-10·CVSS 8.8
CVE-2022-1638 [HIGH] Chromium: CVE-2022-1638 Heap buffer overflow in V8 Internationalization
Chromium: CVE-2022-1638 Heap buffer overflow in V8 Internationalization
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
101.0.1210.47
5/13/2022
101.0.4951.64
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Debian
CVE-2022-1638: chromium - Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0....
vendor_debian·2022·CVSS 8.8
CVE-2022-1638 [HIGH] CVE-2022-1638: chromium - Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0....
Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.64-1)
bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1)
forky: resolved (fixed in 101.0.4951.64-1)
sid: resolved (fixed in 101.0.4951.64-1)
trixie: resolved (fixed in 101.0.4951.64-1)
OSV
f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
osv·2025-12-08
CVE-2022-50620 f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
Syzbot reports a NULL pointer dereference issue as below:
__refcount_add include/linux/refcount.h:193 [inline]
__refcount_inc include/linux/refcount.h:250 [inline]
refcount_inc include/linux/refcount.h:267 [inline]
get_task_struct include/linux/sched/task.h:110 [inline]
kthread_stop+0x34/0x1c0 kernel/kthread.c:703
f2fs_stop_discard_thread+0x3c/0x5c fs/f2fs/segment.c:1638
kill_f2fs_super+0x5c/0x194 fs/f2fs/super.c:4522
deactivate_locked_super+0x70/0xe8 fs/super.c:332
deactivate_super+0xd0/0xd4 fs/super.c:363
cleanup_mnt+0x1f8/0x234 fs/namespace.c:1186
__cleanup_mnt+0x20/0x30 fs/namespace.c:1193
tas
GHSA
GHSA-v898-xxg8-qvgf: Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101
ghsa_unreviewed·2022-07-27
CVE-2022-1638 [HIGH] CWE-787 GHSA-v898-xxg8-qvgf: Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101
Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-1638: Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101
osv·2022-07-26·CVSS 8.8
CVE-2022-1638 [HIGH] CVE-2022-1638: Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101
Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: OS command injection, directory traversal and other vulnerabilities found in Siretta Quartz-Gold and FreshTomato
blogs_talos·2023-01-26·CVSS 8.8
[HIGH] Vulnerability Spotlight: OS command injection, directory traversal and other vulnerabilities found in Siretta Quartz-Gold and FreshTomato
Cisco Talos recently discovered several vulnerabilities in the Siretta Quartz-Gold router. Talos also discovered vulnerabilities in FreshTomato while investigating the Siretta router.
The Siretta Quartz-Gold is an industrial cellular router with several features and services, such as: SSH, UPNP, VPN, SNMP and many others. FreshTomato is an open source firmware based on Linux. The firmware offers several features for Broadcom-based routers.
### Quartz-Gold Vulnerabilities
Several OS command injection vulnerabilities were found which could lead to arbitrary command execution, making them all high risk. TALOS-2022-1607 (CVE-2022-40969) and TALOS-2022-1612 (CVE-2022-40220) can be triggered with HTTP requests, while TALOS-2022-1615 (CVE-2022-38066), TALOS-2022-1638 (CVE-2022-40222) and TALOS
Bugzilla
CVE-2022-50620 kernel: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
bugzilla·2025-12-08
CVE-2022-50620 CVE-2022-50620 kernel: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
CVE-2022-50620 kernel: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to invalidate dcc->f2fs_issue_discard in error path
Syzbot reports a NULL pointer dereference issue as below:
__refcount_add include/linux/refcount.h:193 [inline]
__refcount_inc include/linux/refcount.h:250 [inline]
refcount_inc include/linux/refcount.h:267 [inline]
get_task_struct include/linux/sched/task.h:110 [inline]
kthread_stop+0x34/0x1c0 kernel/kthread.c:703
f2fs_stop_discard_thread+0x3c/0x5c fs/f2fs/segment.c:1638
kill_f2fs_super+0x5c/0x194 fs/f2fs/super.c:4522
deactivate_locked_super+0x70/0xe8 fs/super.c:332
deactivate_super+0xd0/0xd4 fs/super.c:363
cleanup_mnt+0x1f8/0x234 fs/namespace.c:1186
__cleanup_mnt+0x20/0x30
2022-07-26
Published