PT-2022-4823 · Blender+3 · Blender+3

Albin Eldstål-Ahrens

·

Published

2022-01-04

·

Updated

2026-04-16

·

CVE-2022-0545

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blender versions prior to 2.83.19 Blender versions prior to 2.93.8 Blender versions prior to 3.1
Description An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded.
Recommendations For versions prior to 2.83.19, update to version 2.83.19 or later to resolve the issue. For versions prior to 2.93.8, update to version 2.93.8 or later to resolve the issue. For versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting the loading of specially crafted image files until a patch is available.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1579
ALT-PU-2022-2239
BDU:2022-05849
CVE-2022-0545
DLA-3060-1
DSA-5176-1
OPENSUSE-SU-2024:11859-1
OPENSUSE-SU-2025:15755-1
OPENSUSE-SU-2025:15756-1
OPENSUSE-SU-2026:10560-1

Affected Products

Alt Linux
Astra Linux
Blender
Red Os