CVE-2022-0544
24.02.2022, 19:15
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
Vendor | Product | Version |
---|---|---|
blender | blender | 𝑥 < 2.83.19 |
blender | blender | 2.90.0 ≤ 𝑥 < 2.93.8 |
blender | blender | 3.0 ≤ 𝑥 < 3.1 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References