yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-4437
Component Overview
Vulnerability Overview
Name
CVE-2022-4437
Source
NVD (
link
)
Debian (
link
)
Description
Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWEs
CWE-416
Published Date
Dec 14, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html
Release Notes
https://crbug.com/1394692
Permissions Required
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html
Release Notes
https://crbug.com/1394692
Permissions Required
Analysis
#
Affected Component
Analysis
nasm
Patched
Vulnerability Rating
#
8.8
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
nasm
openwrt
master
2.16.01-r1
Not Affected
nasm
openwrt
openwrt-25.12
2.16.01-r1
Not Affected
nasm
yocto
master
3.01
Not Affected
nasm
yocto
scarthgap
2.16.03
Not Affected
Resolved with patches
#
nasm (yocto:kirkstone)
#
Title
Author
Resolve
1
quote_for_pmake: fix counter underrun resulting in segfault
"H. Peter Anvin" <hpa@zytor.com>
CVE-2022-4437