Skip to content

Double Free in bobj.c when using QNX binary plugin

High
ret2libc published GHSA-rjhv-mj4g-j4p5 Sep 2, 2022

Package

rizin (C)

Affected versions

<=0.4.0

Patched versions

0.4.1

Description

Impact

A double free in bobj.c:rz_bin_reloc_storage_free() when freeing relocations generated from QNX binary plugin. A user opening a malicious QNX binary could be affected by this vulnerability, allowing an attacker to execute code on the user's machine.

Patches

58926df

References

#2964

Severity

High

CVE ID

CVE-2022-36043

Weaknesses

Credits