CVE-2021-4022 log

Source
Severity Low
Remote No
Type Denial of service
Description
A specially crafted binary can make Rizin segfault when it tries to analyze it (doing a full analysis with aaa). In rz_core_analysis_type_match retctx structure was initialized on the stack only after a "goto out_function", where a field of that structure was freed. When the goto path is taken, the field is not properly initialized and it could cause a crash of Rizin or have other effects.
Group Package Affected Fixed Severity Status Ticket
AVG-2590 rizin 0.3.1-1 0.3.2-1 Medium Fixed
Date Advisory Group Package Severity Type
04 Apr 2022 ASA-202204-4 AVG-2590 rizin Medium multiple issues
References
https://github.com/rizinorg/rizin/issues/2015
https://github.com/rizinorg/rizin/pull/2031
https://github.com/rizinorg/rizin/commit/21584e416cdcef2fa7d855c5aabf592a965f0e8d
https://github.com/rizinorg/rizin/commit/6ce71d8aa3dafe3cdb52d5d72ae8f4b95916f939