High severity8.8NVD Advisory· Published Apr 15, 2022· Updated Jun 17, 2026
CVE-2022-28042
CVE-2022-28042
Description
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:a:nothings:stb_image.h:2.27:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/nothings/stb/pull/1297nvdPatchThird Party Advisory
- github.com/nothings/stb/issues/1289nvdExploitIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/01/msg00045.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FXLM5XL77SNH4IPTSXOQD7XL4E2EMIN/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I4HXIWU5HBOADXZVMREHT4YTO5WVYXEQ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMBCMJGAZRQS55SNECUWZSC5URVLEZ5R/nvd
News mentions
0No linked articles in our index yet.