CVE-2022-0546: Integer Overflow
Published Feb 24, 2022
·Updated
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Affected Software
8 affected componentsFixes available
debian/blender
2.79.b+dfsg0-7+deb10u12.83.5+dfsg-5+deb11u13.4.1+dfsg-23.6.2+dfsg-2
Blender Blender=2.93.8
Blender Blender=3.0
Fedoraproject Extra Packages For Enterprise Linux=7.0
Fedoraproject Fedora=34
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Feb 24, 2022
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0546?
The severity of CVE-2022-0546 is high.
2
What is the impact of CVE-2022-0546?
CVE-2022-0546 can lead to denial of service, memory corruption, or potentially code execution.
3
Which versions of Blender are affected by CVE-2022-0546?
Blender 3.x and 2.93.8 are affected by CVE-2022-0546.
4
How can an attacker exploit CVE-2022-0546?
An attacker can exploit CVE-2022-0546 by causing out-of-bounds heap access.
5
Are there any patches or fixes available for CVE-2022-0546?
Yes, patches and fixes for CVE-2022-0546 are available. Please refer to the references for more information.