First published: Thu Feb 24 2022(Updated: )
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/blender | 2.79.b+dfsg0-7+deb10u1 2.83.5+dfsg-5+deb11u1 3.4.1+dfsg-2 3.6.2+dfsg-2 | |
Blender | =2.93.8 | |
Blender | =3.0 | |
Fedora EPEL | =7.0 | |
Red Hat Fedora | =34 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-0546 is high.
CVE-2022-0546 can lead to denial of service, memory corruption, or potentially code execution.
Blender 3.x and 2.93.8 are affected by CVE-2022-0546.
An attacker can exploit CVE-2022-0546 by causing out-of-bounds heap access.
Yes, patches and fixes for CVE-2022-0546 are available. Please refer to the references for more information.