PT-2022-23138 · Rizin · Rizin
M4Drat
·
Published
2022-09-06
·
Updated
2023-03-30
·
CVE-2022-36043
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rizin versions 0.4.0 and prior
Description
The issue is related to a double free in bobj.c:rz bin reloc storage free() when freeing relocations generated from qnx binary plugin. A user opening a malicious qnx binary could be affected, allowing an attacker to execute code on the user's machine.
Recommendations
For versions 0.4.0 and prior, apply the patch contained in commit number a3d50c1ea185f3f642f2d8180715f82d98840784 to resolve the issue. As a temporary workaround, consider avoiding the use of the qnx binary plugin until the patch is applied.
Exploit
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rizin