Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when parsing Mach-O files. A user opening a malicious Mach-O file could be affected by this vulnerability, allowing an attacker to execute code on the user's machine. Commit number 7323e64d68ecccfb0ed3ee480f704384c38676b2 contains a patch.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36041.json"
}{
"cpe": "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.4.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36041.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"327526120902679820872561839682960903069",
"319297354910359186681626770563970596686",
"264842803861253436629927771693511863664",
"96108992862053433724243717082299236842",
"240964683627962053136876806499112648516",
"157439466103990847957270435422679346623",
"322463205339314604258984110677443220345",
"41381418003445335430488399734175224309",
"30608149533698867710845072245353121680"
],
"threshold": 0.9
},
"id": "CVE-2022-36041-8687a8e3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/7323e64d68ecccfb0ed3ee480f704384c38676b2",
"target": {
"file": "librz/bin/format/mach0/mach0.c"
}
}
]
"2026-08-12T13:01:22Z"