CVE-2023-22485
MEDIUMGithub Cmark-gfm < 0.29.0.gfm.7 - Out-of-Bounds Access
Title source: ruleDescription
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown document can trigger an out-of-bounds read in the `validate_protocol` function. We believe this bug is harmless in practice, because the out-of-bounds read accesses `malloc` metadata without causing any visible damage.This vulnerability has been patched in 0.29.0.gfm.7.
Scores
CVSS v3
5.3
EPSS
0.0007
EPSS Percentile
21.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-125
CWE-91
Status
published
Products (1)
github/cmark-gfm
< 0.29.0.gfm.7
Published
Jan 24, 2023
Tracked Since
Feb 18, 2026