Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
{
"cna_assigner": "@huntrdev",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2301.json",
"cwe_ids": [
"CWE-126"
]
}{
"cpe": "cpe:2.3:a:chafa_project:chafa:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.10.3"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T02:23:51Z"
[
{
"target": {
"file": "tools/chafa/xwd-loader.c"
},
"id": "CVE-2022-2301-320f80fb",
"digest": {
"line_hashes": [
"203232558762889153420516075075387395924",
"13636168278890827668067462786301782529",
"97100102561598080810634613044372584890",
"17532002719855215703891836387141219975",
"178678871631442519793781407859896644007",
"51722434347214541572304996013288924968",
"247079002863132663669763881473607099128",
"213948690984732024312150608866565716500",
"124010627984799020266829572696286873134",
"5068299108077968519173033637814211114",
"195678307287432529250540554401480462556",
"150586038307919581546159217970997478536",
"170044852444881709640158614220024279796",
"14432220516600885945620061839813288661",
"106655158698239002892167051200676570504",
"15037652897201797403748947968315107443",
"69511253130142726082231239264513324045",
"185934106258197229101292816093187558388",
"295411536194175417149970537923923678618",
"74169519467869755598692706401887784539",
"183024231059784991236980334056549665060",
"158378741482456244964632790394158081992",
"214826925478979594748106571824459823075",
"284436597950451259785421907994577266758",
"98016545567263291903846262532856032748",
"174966009299161603282282555730400484448",
"243661003570088670872015174664891956205",
"268033106026074193473114637574300058820",
"146368823421098985061204464244079771351",
"110163775558687265291134824170188358980",
"300599127134701533981325183323081454733",
"217753877710706705639953560821802183618",
"221659514095685382463431357017942476416",
"155032038334169820372564919070134255833",
"293828782584640469011058574296399140071",
"100059713642664117970393302756717122413",
"116081504549615376717393166118137191380",
"170882826457480693253337281058376873556",
"289410420806442949210403511730701005061",
"338189899060704761089435372313553358035",
"188579739070431590116959655142757405996",
"119234823882790718561443797400457720572",
"158064760826858568626568122040327282794",
"132024154021321282005522944924230499034",
"255707115062502317056711408245203469947",
"14276374210620003097279866038338185965",
"260960298883376833200275110102718181367",
"39330253945764862631845416641224287476"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/hpjansson/chafa/commit/56fabfa18a6880b4cb66047fa6557920078048d9"
},
{
"target": {
"function": "load_header",
"file": "tools/chafa/xwd-loader.c"
},
"id": "CVE-2022-2301-60dd8051",
"digest": {
"function_hash": "217736332156326124632171173199005072722",
"length": 2214.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/hpjansson/chafa/commit/56fabfa18a6880b4cb66047fa6557920078048d9"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2301.json"