CVE-2022-0544: Integer Underflow
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0544?
CVE-2022-0544 is a vulnerability in Blender that allows an attacker to read sensitive data using a crafted DDS image file.
Which versions of Blender are affected by CVE-2022-0544?
Blender versions prior to 2.83.19, 2.93.8, and 3.1 are affected by CVE-2022-0544.
How can an attacker exploit CVE-2022-0544?
An attacker can exploit CVE-2022-0544 by using a crafted DDS image file to trigger an integer underflow in the DDS loader of Blender, leading to an out-of-bounds read and the potential for reading sensitive data.
What is the severity of CVE-2022-0544?
CVE-2022-0544 has a severity score of 5.5, which is considered medium.
How can I fix CVE-2022-0544 in Blender?
To fix CVE-2022-0544, you should update Blender to version 2.83.19, 2.93.8, or 3.1 or apply the corresponding security patches provided by the Blender project or your Linux distribution.