CVE-2022-26704: Buffer Overflow
A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.4. An app may be able to gain elevated privileges.
Other sources
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
AMD. A memory corruption issue was addressed with improved state management.
— Apple
apache. Multiple issues were addressed by updating apache to version 2.4.53.
— Apple
AppleGraphicsControl. A memory corruption issue was addressed with improved input validation.
— Apple
AppleMobileFileIntegrity. An issue in the handling of environment variables was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-32832
- CVE-2022-32826
- CVE-2022-32797
- CVE-2022-32853
- CVE-2022-32851
- CVE-2022-32831
- CVE-2022-32910
- CVE-2022-32825
- CVE-2022-32820
- CVE-2022-32805
- CVE-2022-32849
- CVE-2022-32839
- CVE-2022-32781
- CVE-2022-32819
- CVE-2022-32787
- CVE-2022-32785
- CVE-2022-32812
- CVE-2022-32811
- CVE-2022-32815
- CVE-2022-32813
- CVE-2021-30946
- CVE-2022-32823
- CVE-2022-32814
- CVE-2022-32786
- CVE-2022-32800
- CVE-2022-32838
- CVE-2022-32843
- CVE-2022-32857
- CVE-2022-32807
- CVE-2022-26704
- CVE-2022-32834
- CVE-2022-0156
- CVE-2022-0158
- CVE-2022-32860
- CVE-2022-32847
- CVE-2022-32848
- CVE-2022-32842
- CVE-2022-32799
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-32837
- CVE-2022-26772
- CVE-2022-26741
- CVE-2022-26742
- CVE-2022-26749
- CVE-2022-26750
- CVE-2022-26752
- CVE-2022-26753
- CVE-2022-26754
- CVE-2021-44224
- CVE-2021-44790
- CVE-2022-22719
- CVE-2022-22720
- CVE-2022-22721
- CVE-2022-26751
- CVE-2022-26707
- CVE-2022-26697
- CVE-2022-26698
- CVE-2022-26736
- CVE-2022-26737
- CVE-2022-26738
- CVE-2022-26739
- CVE-2022-26740
- CVE-2022-32783
- CVE-2022-26694
- CVE-2022-26721
- CVE-2022-26722
- CVE-2022-26763
- CVE-2022-26711
- CVE-2022-26725
- CVE-2022-26720
- CVE-2022-26769
- CVE-2022-26770
- CVE-2022-26748
- CVE-2022-26756
- CVE-2022-26701
- CVE-2022-26768
- CVE-2022-26758
- CVE-2022-26743
- CVE-2022-26714
- CVE-2022-26757
- CVE-2022-26764
- CVE-2022-26765
- CVE-2022-26706
- CVE-2022-26767
- CVE-2022-32882
- CVE-2022-32790
- CVE-2022-26776
- CVE-2022-26708
- CVE-2022-26775
- CVE-2022-0778
- CVE-2022-23308
- CVE-2022-48575
- CVE-2022-32794
- CVE-2022-22617
- CVE-2022-26712
- CVE-2022-26727
- CVE-2022-32782
- CVE-2022-26693
- CVE-2022-26746
- CVE-2022-26731
- CVE-2022-26766
- CVE-2022-26715
- CVE-2022-26718
- CVE-2022-26723
- CVE-2022-26728
- CVE-2022-42857
- CVE-2022-26726
- CVE-2022-26755
- CVE-2022-26696
- CVE-2022-26700
- CVE-2022-26709
- CVE-2022-26710
- CVE-2022-26717
- CVE-2022-26716
- CVE-2022-26719
- CVE-2022-22677
- CVE-2022-26745
- CVE-2022-26761
- CVE-2022-26762
- CVE-2022-0530
- CVE-2018-25032
- CVE-2021-45444
- CVE-2022-26702
- CVE-2022-26744
- CVE-2022-26771
- CVE-2022-22673
- CVE-2022-26703
- CVE-2022-26760
- CVE-2015-4142
Frequently Asked Questions
What is CVE-2022-26704?
CVE-2022-26704 is a vulnerability related to a validation issue in the handling of symlinks in Apple Spotlight.
How does CVE-2022-26704 affect Apple software?
CVE-2022-26704 affects Apple software including macOS Big Sur (up to version 11.6.8) and macOS Monterey (up to version 12.4).
What is the severity of CVE-2022-26704?
The severity of CVE-2022-26704 has not been specified.
How can I fix CVE-2022-26704?
To fix CVE-2022-26704, update your Apple software to the recommended versions: macOS Big Sur 11.6.8 or macOS Monterey 12.4.
Where can I find more information about CVE-2022-26704?
More information about CVE-2022-26704 can be found on the Apple support page: [https://support.apple.com/en-us/HT213257](https://support.apple.com/en-us/HT213257)