Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when parsing Mach-O files. A user opening a malicious Mach-O file could be affected by this vulnerability, allowing an attacker to execute code on the user's machine. Commit number 7323e64d68ecccfb0ed3ee480f704384c38676b2 contains a patch.
{
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36041.json",
"cna_assigner": "GitHub_M"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36041.json"
"2026-04-11T23:41:58Z"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"327526120902679820872561839682960903069",
"319297354910359186681626770563970596686",
"264842803861253436629927771693511863664",
"96108992862053433724243717082299236842",
"240964683627962053136876806499112648516",
"157439466103990847957270435422679346623",
"322463205339314604258984110677443220345",
"41381418003445335430488399734175224309",
"30608149533698867710845072245353121680"
]
},
"source": "https://github.com/rizinorg/rizin/commit/7323e64d68ecccfb0ed3ee480f704384c38676b2",
"id": "CVE-2022-36041-8687a8e3",
"signature_type": "Line",
"target": {
"file": "librz/bin/format/mach0/mach0.c"
}
}
]