CVE-2022-26772: Buffer Overflow
Published May 16, 2022
·Updated
AMD. A memory corruption issue was addressed with improved state management.
Credit
an anonymous researcher, ABC Research s.r.o, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Wojciech Reguła@@_r3ggi(SecuRing), Qi Sun(Trend Micro), Robert Ai(Trend Micro), Ye Zhang@@co0py_Cat(Baidu Security), Jon Thompson(Evolve), IA), Yonghwi Jin@@jinmo123(Theori), Linus Henze(Pinauten GmbH), actae0n(Blacksun Hackers Club working with Trend Micro Zero Day Initiative), Andrew Williams(Google), Avi Drissman(Google), Liu Long(Ant Security Light), Antonio Zekic@@antoniozekic, Jeonghoon Shin(Theori working with Trend Micro Zero Day Initiative), Jack Dates(RET2 Systems Inc), chenyuwang@@mzzzz__(Tencent Security Xuanwu Lab), Jordy Zomer@@pwningsystems, Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs), Ned Williamson(Google Project Zero), Arsenii Kostromin (0x3c3e)(Microsoft), Jonathan Bar Or(Microsoft), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Yuebin Sun@@yuebinsun2020(Tencent Security Xuanwu Lab), Max Shavrick@@_mxms(the Google Security Team), Zubair Ashraf(Crowdstrike), CVE-2022-0778, CVE-2022-23308, Paul Walker(Bury), Nathaniel Ekoniak(Ennate Technologies), Mickey Jin@@patch1t, @@gorelics, Peter Nguyễn Vũ Hoàng(STAR Labs), Felix Poulin-Belanger, Gergely Kalman@@gergely_kalman(Mandiant), (Mandiant), Joshua Mason(Mandiant), Antonio Cheong Yu Xuan(YCISCQ), Arsenii Kostromin (0x3c3e), Ron Waisberg(SecuRing), an anonymous researcher(SecuRing), (Perception Point), Ron Hass@@ronhass7(Perception Point), ryuzaki, Chijin Zhou(ShuiMuYuLin Ltd), Tsinghua wingtecher lab, Jeonghoon Shin(Theori), SorryMybad@@S0rryMybad(Kunlun Lab), Dongzhuo Zhao(ADLab of Venustech), Scarlet Raine, Wang Yu(Cyberserval), CVE-2022-0530, Tavis Ormandy, CVE-2021-45444
Affected Software
2 affected componentsFixes available
macOS<12.4
12.4
macOS>=12.0<12.4
Event History
May 16, 2022
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
May 26, 2022
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-26772.
2
What is the title of the vulnerability?
The title of the vulnerability is 'AMD. A memory corruption issue was addressed with improved state management.'
3
What is the affected software?
The affected software is macOS Monterey version up to 12.4.
4
How was the vulnerability addressed?
The memory corruption issue was addressed with improved state management.
5
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following link: [Apple Support](https://support.apple.com/en-us/HT213257).