blender: Null pointer reference in blender thumbnail extractor
Published Aug 16, 2022
7.5
HIGHCVSS 3.1
EPSS 1.70%
Description
A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.
Affected products
- Vendor n/a Product Blender Defaultn/a
- Version Blender 3.3.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Blender | n/a |
|
No data.
OSE-OSC-1.3-RHEL-8
openshift-sandboxed-containers/osc-monitor-rhel8:1.3.1-5
Fixed · RHSA-2022:7058
OSE-OSC-1.3-RHEL-8
openshift-sandboxed-containers/osc-must-gather-rhel8:1.3.1-6
Fixed · RHSA-2022:7058
OSE-OSC-1.3-RHEL-8
openshift-sandboxed-containers/osc-operator-bundle:1.3.1-10
Fixed · RHSA-2022:7058
OSE-OSC-1.3-RHEL-8
openshift-sandboxed-containers/osc-rhel8-operator:1.3.1-5
Fixed · RHSA-2022:7058
| Product | Package | State | Advisory |
|---|---|---|---|
| OSE-OSC-1.3-RHEL-8 | openshift-sandboxed-containers/osc-monitor-rhel8:1.3.1-5 | Fixed | RHSA-2022:7058 |
| OSE-OSC-1.3-RHEL-8 | openshift-sandboxed-containers/osc-must-gather-rhel8:1.3.1-6 | Fixed | RHSA-2022:7058 |
| OSE-OSC-1.3-RHEL-8 | openshift-sandboxed-containers/osc-operator-bundle:1.3.1-10 | Fixed | RHSA-2022:7058 |
| OSE-OSC-1.3-RHEL-8 | openshift-sandboxed-containers/osc-rhel8-operator:1.3.1-5 | Fixed | RHSA-2022:7058 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-2832 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2118556 Issue Tracking
- https://developer.blender.org/D15463 x_refsource_MISCPatchVendor Advisory
- https://developer.blender.org/T99706 x_refsource_MISCExploitPatchVendor Advisory
- https://developer.blender.org/rB00dc7477022acdd969e4d709a235c0be819efa6c x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2832
- https://www.cve.org/CVERecord?id=CVE-2022-2832
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2832 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2118556 | Issue Tracking | |
| https://developer.blender.org/D15463 | x_refsource_MISCPatchVendor Advisory | |
| https://developer.blender.org/T99706 | x_refsource_MISCExploitPatchVendor Advisory | |
| https://developer.blender.org/rB00dc7477022acdd969e4d709a235c0be819efa6c | x_refsource_MISCPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2832 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2832 |
Change history (0)
No recorded changes yet.