CVE-2022-2853
published 2022-09-26CVE-2022-2853: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.76%
75.5th percentile
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 104.0.5112.101-1~deb11u1 | 104.0.5112.101-1~deb11u1 |
| chromium | chromium | >= 0 < 104.0.5112.101-1 | 104.0.5112.101-1 |
| chromium | chromium | >= 0 < 104.0.5112.101-1 | 104.0.5112.101-1 |
| chromium | chromium | >= 0 < 104.0.5112.101-1 | 104.0.5112.101-1 |
| debian | chromium | < chromium 104.0.5112.101-1 (bookworm) | chromium 104.0.5112.101-1 (bookworm) |
| fedoraproject | fedora | — | — |
| chrome | < 104.0.5112.101 | 104.0.5112.101 | |
| chrome | >= unspecified < 104.0.5112.101 | 104.0.5112.101 | |
| linux | linux_kernel | >= 0 < 4.4.0-222.255 | 4.4.0-222.255 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 104.0.5112.101 Downloads heap-based overflow (EUVD-2022-35087 / Nessus ID 211177)
vuldb·2026-05-27·CVSS 8.8
CVE-2022-2853 [HIGH] Google Chrome up to 104.0.5112.101 Downloads heap-based overflow (EUVD-2022-35087 / Nessus ID 211177)
A vulnerability was found in Google Chrome and classified as critical. This affects an unknown part of the component Downloads. Such manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2022-2853. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-xmjv-jv6c-x229: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104
ghsa_unreviewed·2022-09-27
CVE-2022-2853 [HIGH] CWE-787 GHSA-xmjv-jv6c-x229: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-2853: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104
osv·2022-09-26·CVSS 8.8
CVE-2022-2853 [HIGH] CVE-2022-2853: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-03-22·CVSS 7.8
CVE-2022-0492 linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly use this to gain
elevated privileges. (CVE
Red Hat
kernel: scsi: qla2xxx: Implement ref count for SRB
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49159 [MEDIUM] CWE-401 kernel: scsi: qla2xxx: Implement ref count for SRB
kernel: scsi: qla2xxx: Implement ref count for SRB
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Implement ref count for SRB
The timeout handler and the done function are racing. When
qla2x00_async_iocb_timeout() starts to run it can be preempted by the
normal response path (via the firmware?). qla24xx_async_gpsc_sp_done()
releases the SRB unconditionally. When scheduling back to
qla2x00_async_iocb_timeout() qla24xx_async_abort_cmd() will access an freed
sp->qpair pointer:
qla2xxx [0000:83:00.0]-2871:0: Async-gpsc timeout - hdl=63d portid=234500 50:06:0e:80:08:77:b6:21.
qla2xxx [0000:83:00.0]-2853:0: Async done-gpsc res 0, WWPN 50:06:0e:80:08:77:b6:21
qla2xxx [0000:83:00.0]-2854:0: Async-gpsc OUT WWPN 20:45:00:27:f8:75:33:00 speeds=2c00 speed=0400.
qla
Microsoft
Chromium: CVE-2022-2853 Heap buffer overflow in Downloads
vendor_msrc·2022-08-09·CVSS 8.8
CVE-2022-2853 [HIGH] Chromium: CVE-2022-2853 Heap buffer overflow in Downloads
Chromium: CVE-2022-2853 Heap buffer overflow in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
104.0.1293.63
8/19/2022
104.0.5112.102
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browse
Debian
CVE-2022-2853: chromium - Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.511...
vendor_debian·2022·CVSS 8.8
CVE-2022-2853 [HIGH] CVE-2022-2853: chromium - Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.511...
Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.101-1)
bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1)
forky: resolved (fixed in 104.0.5112.101-1)
sid: resolved (fixed in 104.0.5112.101-1)
trixie: resolved (fixed in 104.0.5112.101-1)
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/169459/Chrome-offline_items_collection-OfflineContentAggregator-OnItemRemoved-Heap-Buffer-Overflow.htmlhttps://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.htmlhttps://crbug.com/1350097https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/http://packetstormsecurity.com/files/169459/Chrome-offline_items_collection-OfflineContentAggregator-OnItemRemoved-Heap-Buffer-Overflow.htmlhttps://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.htmlhttps://crbug.com/1350097https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/https://issues.chromium.org/issues/40060491
2022-09-26
Published