CVE-2022-44638: Buffer Overflow
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterizeedges8 due to an integer overflow in pixmansamplefloory.
Other sources
Pixman could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write flaw in the rasterizeedges8 function in libpixman. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/pixmanto a version that resolves this vulnerability.Fixed in 0.36.0-1+deb10u1Fixed in 0.40.0-1.1~deb11u1Fixed in 0.42.2-1 - Upgrade
Upgrade
redhat/Pixmanto a version that resolves this vulnerability.Fixed in 0.42.2
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44638?
The severity of CVE-2022-44638 is high, with a severity value of 8.8.
What is the affected software for CVE-2022-44638?
The affected software for CVE-2022-44638 includes Pixman versions up to exclusive 0.42.2, Debian Linux 10.0 and 11.0, and Fedora versions 35, 36, and 37.
What is the vulnerability description of CVE-2022-44638?
CVE-2022-44638 is a heap-based buffer overflow vulnerability in Pixman's libpixman, specifically in the rasterize_edges_8 function, caused by an integer overflow in pixman_sample_floor_y.
How can I fix CVE-2022-44638?
To fix CVE-2022-44638, update to Pixman version 0.42.2 or higher, Debian Linux versions 10.0-1+deb10u1, 11.0-1.1~deb11u1, or the pixman package 0.42.2-1 for Debian. For Fedora, update to versions 36 or 37.
What are the references for CVE-2022-44638?
The references for CVE-2022-44638 are: [1] GitLab issue: https://gitlab.freedesktop.org/pixman/pixman/-/issues/63, [2] Debian Security Tracker: https://security-tracker.debian.org/tracker/CVE-2022-44638, [3] CVE-2022-44638 on CVE website: https://www.cve.org/CVERecord?id=CVE-2022-44638.