« Volver al listado

CVE-2022-38216

Estado: ModificadaAlta (7.5)—

An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-38216",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Mapbox",
          "product": "Mapbox",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "10.6.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-16T01:15:14.360",
  "references": [
    {
      "url": "https://github.com/mapbox/mapbox-maps-android/releases/tag/android-v10.6.1",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://github.com/mapbox/mapbox-maps-android/releases/tag/android-v10.6.1",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-assign@fb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially crashing the Mapbox process."
    },
    {
      "lang": "es",
      "value": "Se presenta un desbordamiento de enteros en la biblioteca de código cerrado gl-native de Mapbox versiones anteriores a 10.6.1, que es incluida con varios productos de Mapbox, incluyendo las bibliotecas de código abierto. El desbordamiento es causado por grandes valores de altura y anchura de la imagen cuando es creada una nueva imagen y permite escrituras fuera de límites, lo que potencialmente puede bloquear el proceso de Mapbox."
    }
  ],
  "lastModified": "2026-06-17T04:56:18.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mapbox:maps_software_development_kit:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88C156D3-10A4-4AC0-8A21-CD494993362A",
              "versionEndExcluding": "10.6.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}