CVE-2022-1296: Out-of-bounds read in `r_bin_ne_get_relocs` function in radareorg/radare2
Out-of-bounds read in rbinnegetrelocs function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1296?
CVE-2022-1296 is an out-of-bounds read vulnerability in the r_bin_ne_get_relocs function in the radareorg/radare2 GitHub repository prior to version 5.6.8.
How does CVE-2022-1296 impact the affected software?
CVE-2022-1296 may allow attackers to read sensitive information or cause a crash.
What is the severity of CVE-2022-1296?
The severity of CVE-2022-1296 is rated as critical with a CVSS score of 9.1.
How can I fix CVE-2022-1296?
To fix CVE-2022-1296, it is recommended to update the radareorg/radare2 software to version 5.6.8 or later.
Where can I find more information about CVE-2022-1296?
More information about CVE-2022-1296 can be found at the following references: [GitHub Commit](https://github.com/radareorg/radare2/commit/153bcdc29f11cd8c90e7d639a7405450f644ddb6) and [Huntr Bounties](https://huntr.dev/bounties/52b57274-0e1a-4d61-ab29-1373b555fea0).