yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-44638
Component Overview
Vulnerability Overview
Name
CVE-2022-44638
Source
NVD (
link
)
Debian (
link
)
Description
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.
CWEs
CWE-190
CWE-190
Published Date
Nov 3, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://packetstormsecurity.com/files/170121/pixman-pixman_sample_floor_y-Integer-Overflow.html
Exploit
http://www.openwall.com/lists/oss-security/2022/11/05/1
Mailing List
https://gitlab.freedesktop.org/pixman/pixman/-/issues/63
Exploit
https://lists.debian.org/debian-lts-announce/2022/11/msg00008.html
Mailing List
https://www.debian.org/security/2022/dsa-5276
Third Party Advisory
http://packetstormsecurity.com/files/170121/pixman-pixman_sample_floor_y-Integer-Overflow.html
Exploit
http://www.openwall.com/lists/oss-security/2022/11/05/1
Mailing List
https://gitlab.freedesktop.org/pixman/pixman/-/issues/63
Exploit
https://lists.debian.org/debian-lts-announce/2022/11/msg00008.html
Mailing List
https://www.debian.org/security/2022/dsa-5276
Third Party Advisory
Analysis
#
Affected Component
Analysis
pixman
Patched
Vulnerability Ratings
#
8.8
CVSSv31
8.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
pixman
buildroot
2025.02.x
0.44.2
Not Affected
pixman
buildroot
master
0.46.4
Not Affected
pixman
openwrt
master
0.46.4-r1
Not Affected
pixman
openwrt
openwrt-25.12
0.46.4-r1
Not Affected
pixman
yocto
master
0.46.4
Not Affected
pixman
yocto
scarthgap
0.42.2
Not Affected
Resolved with patches
#
pixman (yocto:kirkstone)
#
Title
Author
Resolve
1
Avoid integer overflow leading to out-of-bounds write
Matt Turner <mattst88@gmail.com>
CVE-2022-44638