Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from Luac files. A user opening a malicious Luac file could be affected by this vulnerability, allowing an attacker to execute code on the user's machine. Commits 07b43bc8aa1ffebd9b68d60624c9610cf7e460c7 and 05bbd147caccc60162d6fba9baaaf24befa281cd contain fixes for the issue.
{
"cwe_ids": [
"CWE-787"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36044.json"
}{
"cpe": "cpe:2.3:a:rizin:rizin:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.4.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T02:07:48Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 171.0,
"function_hash": "28336237988227516751654490806948321231"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-02255510",
"target": {
"function": "entries",
"file": "librz/bin/p/bin_luac.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 172.0,
"function_hash": "306057957229487872549493392817091791884"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-404ba7f2",
"target": {
"function": "strings",
"file": "librz/bin/p/bin_luac.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 172.0,
"function_hash": "252729918656464554439944247266347854871"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-436ae0fe",
"target": {
"function": "symbols",
"file": "librz/bin/p/bin_luac.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"9114179400956166026806490749080465910",
"141647950716231033960712452470651352338",
"203371619328472460951370656405742994406",
"122122810315559685324249356524337327696"
]
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/07b43bc8aa1ffebd9b68d60624c9610cf7e460c7",
"id": "CVE-2022-36044-44a613b2",
"target": {
"file": "librz/bin/bobj.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"115585023725065363652681674793707175144",
"273439764585809750213454451052162252740",
"191292091907489063763726256326437448179",
"138810595769389364588559812963404100011",
"289620902878724183091272464250448600138",
"319719830351657164735484270487854214342",
"180255372665746641547268191931774641874",
"14715478804584404206664639608337111236"
]
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/07b43bc8aa1ffebd9b68d60624c9610cf7e460c7",
"id": "CVE-2022-36044-67f6ae31",
"target": {
"file": "librz/bin/format/luac/luac_bin.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"215238511146071959105826577505660474586",
"66060149461895242802979092227113351473",
"42589326598188715315937710900959790389",
"222659060936723743086143318393259777539"
]
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-96bc45bc",
"target": {
"file": "librz/bin/format/luac/luac_common.h"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2726.0,
"function_hash": "305525324468473274269039272146284936516"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/07b43bc8aa1ffebd9b68d60624c9610cf7e460c7",
"id": "CVE-2022-36044-9a90e509",
"target": {
"function": "_luac_build_info",
"file": "librz/bin/format/luac/luac_bin.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"308422643457504197492340161132014256903",
"313577405541504920552626088480852156484",
"182536247355538325561453192799138828085",
"280911294105887960003119081278772202466",
"235513899159431505666598529954868446832",
"56106653759624056658576124110026778328",
"122920314377899139662415964241884054822",
"151288420630896594527147665668694954630",
"251689274713171151106799996683496026050",
"73453512914809939399816845345989206454",
"189848249006156320010998401200315453621",
"196707338844380567510450891717128929048",
"164098985302875216011016147494677328843",
"236280288762220040007492909589209415699",
"240178048775285470049141896548078994926",
"138838857590216638349736627480080730335"
]
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-b2e40850",
"target": {
"file": "librz/bin/p/bin_luac.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2649.0,
"function_hash": "50073762455585324533215928909240578951"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-d2fd4c86",
"target": {
"function": "_luac_build_info",
"file": "librz/bin/format/luac/luac_bin.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"252205475323294732752278693728436028830",
"334066345921952954860999791829636130550",
"282677892567176125107188847410522425800",
"330006069739434744685023427164991455787",
"238543705810071242852947134547501051048",
"153963422786010555593739541920249009115",
"189043760029999044982986608663035338395",
"56998609347991406818697065553153056149",
"227536089638478834880352669493404406981",
"175814312047946738247223139596855782967",
"220452457583358943434763786503148749073",
"216805070290311661763381341406215945410",
"122704952267548422693878718564043970803",
"132947213507933754871402467852137590462",
"91275093205121414778316144224680581935",
"317018977627274415377241601098247895505",
"320343190527266891490224183939003861096",
"145428058605514661581364240212479969980",
"173433655421120571658847526707038905099",
"113840130516641668664384536118328417156",
"142708458415929500084099930591406599842",
"175022062646381733741521996605055365379",
"9715558010893518721467083729643507964",
"128827854173291677637692381698034687749",
"73472697503353922876363948703711129572",
"49068717840341500186817485316909757709",
"28002282386520737833308562492126661573",
"44263513939295057532219918830089846261",
"166073781429652841200006180061743053424",
"283361230661348566426572852467501822035",
"74212477413336032017039098530831859544",
"186128344519738149095785108613604479531",
"276935133302620751152661939189914938970",
"68420550256084221715534451073185287698",
"66956279112476318139293953471192148040",
"159821812822246712815984443629058746358",
"258172977822304806436483916709551443517",
"120794518517878873135236383577107567597",
"58401116060243310906039826549146945350",
"37284849157195768116786692960000507379",
"230339114928497989943541444727631298223",
"158462573040393123869248523495872984808",
"137069407366586098850970930894478436903",
"8975168845697350909571301749040851307",
"16339195404029936186331779280522897153",
"308810947856687826062847163980355494119"
]
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-e8c14890",
"target": {
"file": "librz/bin/format/luac/luac_bin.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 775.0,
"function_hash": "146566167267951156637636190157137463324"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/07b43bc8aa1ffebd9b68d60624c9610cf7e460c7",
"id": "CVE-2022-36044-f9e4e8f1",
"target": {
"function": "classes_from_symbols",
"file": "librz/bin/bobj.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 89.0,
"function_hash": "299776846852323747763918371950927746366"
},
"signature_version": "v1",
"source": "https://github.com/rizinorg/rizin/commit/05bbd147caccc60162d6fba9baaaf24befa281cd",
"id": "CVE-2022-36044-febbbd38",
"target": {
"function": "try_free_empty_list",
"file": "librz/bin/format/luac/luac_bin.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36044.json"