Vulnerability Description
DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during processing of a 3rd party Android APK file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redex | < 2022-11-04 |
Related Weaknesses (CWE)
References
- https://github.com/facebook/redex/commit/3b44c640346b77bfb7ef36e2413688dd460288dPatchThird Party Advisory
- https://github.com/facebook/redex/commit/3b44c640346b77bfb7ef36e2413688dd460288dPatchThird Party Advisory
FAQ
What is CVE-2022-36938?
CVE-2022-36938 is a vulnerability with a CVSS score of 9.8 (CRITICAL). DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during proc...
How severe is CVE-2022-36938?
CVE-2022-36938 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-36938?
Check the references section above for vendor advisories and patch information. Affected products include: Facebook Redex.