CVE-2022-21711 - CVE House
Back to Database
Status published High CVE-2022-21711

Out-of-bounds Read lead to application crashes or information leakage in ELF parsing.

Vulnerability Description

elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By constructing a special format ELF file, the information of any address can be leaked. elfspirit version 1.1 contains a patch for this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-21711

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

liyansong2018

View all reports →

Affected Software

elfspirit
Vulnerable Versions:
< 1.1

Timeline

Official Publish: January 24th, 2022
Last Modified: April 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Weaknesses (CWE)