VYPR
Unrated severityNVD Advisory· Published Dec 14, 2022· Updated Apr 22, 2025

CVE-2022-44910

CVE-2022-44910

Description

Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Heap buffer overflow in Binbloom 2.0's read_pointer function allows denial of service via crafted input.

Vulnerability

A heap buffer overflow vulnerability exists in Binbloom 2.0 (and possibly earlier versions) within the read_pointer function at src/helpers.c:67 [1]. The function reads a 4-byte value from a heap-allocated buffer without proper bounds validation, leading to a read past the allocated region. This occurs during the compute_candidates and find_base_address routines when processing a malformed input file [1].

Exploitation

An attacker can exploit this vulnerability by providing a specially crafted binary file to Binbloom. No authentication or special privileges are required as the tool is typically run on user-supplied files. The overflow is triggered when read_pointer attempts to read at an address beyond the allocated heap buffer, resulting in an AddressSanitizer-detected heap buffer overflow [1]. The crash reproduced on the latest commit (b9aada98) confirms the issue is present in the current codebase [1].

Impact

Successful exploitation leads to a program crash, causing denial of service. The overflow is a read operation, so it may also result in disclosure of adjacent heap memory, potentially leaking sensitive data. The reference demonstrates only a crash, but memory corruption could occur in other scenarios [1].

Mitigation

As of the latest commit (b9aada98) and Binbloom 2.0, no official patch has been released [1]. Users should avoid processing untrusted input files with Binbloom until a fix is available. No other workaround is documented.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.