CVE-2022-24724: Integer overflow in table parsing extension leads to heap memory corruption
cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing table.c:rowfromstring may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16MAX columns. The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution depending on how and where cmark-gfm is used. If cmark-gfm is used for rendering remote user controlled markdown, this vulnerability may lead to Remote Code Execution (RCE) in applications employing affected versions of the cmark-gfm library. This vulnerability has been patched in the following cmark-gfm versions 0.29.0.gfm.3 and 0.28.3.gfm.21. A workaround is available. The vulnerability exists in the table markdown extensions of cmark-gfm. Disabling the table extension will prevent this vulnerability from being triggered.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24724?
CVE-2022-24724 is an integer overflow vulnerability in cmark-gfm that may lead to heap memory corruption when parsing tables.
What is the severity of CVE-2022-24724?
The severity of CVE-2022-24724 is critical (9.8 out of 10).
How does CVE-2022-24724 affect GitHub's cmark-gfm?
GitHub's cmark-gfm versions up to 0.28.3.gfm.21 are affected by CVE-2022-24724.
How do I fix CVE-2022-24724 in cmark-gfm?
Update cmark-gfm to version 0.29.0.gfm.3 or later to fix CVE-2022-24724.
Are Fedora 34, 35, and 36 affected by CVE-2022-24724?
Yes, Fedora 34, 35, and 36 are affected by CVE-2022-24724.