CVE-2022-36041

Source
https://cve.org/CVERecord?id=CVE-2022-36041
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36041.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-36041
Aliases
  • GHSA-2c7m-2f37-mr5m
Published
2022-09-06T00:00:00Z
Modified
2026-04-11T23:41:58.980477Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Rizin Out-of-bounds Write vulnerability in Mach-O binary plugin
Details

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when parsing Mach-O files. A user opening a malicious Mach-O file could be affected by this vulnerability, allowing an attacker to execute code on the user's machine. Commit number 7323e64d68ecccfb0ed3ee480f704384c38676b2 contains a patch.

Database specific
{
    "cwe_ids": [
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36041.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/rizinorg/rizin

Affected ranges

Type
GIT
Repo
https://github.com/rizinorg/rizin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36041.json"
vanir_signatures_modified
"2026-04-11T23:41:58Z"
vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "327526120902679820872561839682960903069",
                "319297354910359186681626770563970596686",
                "264842803861253436629927771693511863664",
                "96108992862053433724243717082299236842",
                "240964683627962053136876806499112648516",
                "157439466103990847957270435422679346623",
                "322463205339314604258984110677443220345",
                "41381418003445335430488399734175224309",
                "30608149533698867710845072245353121680"
            ]
        },
        "source": "https://github.com/rizinorg/rizin/commit/7323e64d68ecccfb0ed3ee480f704384c38676b2",
        "id": "CVE-2022-36041-8687a8e3",
        "signature_type": "Line",
        "target": {
            "file": "librz/bin/format/mach0/mach0.c"
        }
    }
]