{"id":"CVE-2022-38072","details":"An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.","aliases":["GHSA-v5hv-4pw3-q6h9"],"modified":"2026-08-12T13:33:09.837764Z","published":"2023-04-03T15:07:21.146Z","database_specific":{"cna_assigner":"talos","cwe_ids":["CWE-118"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38072.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Master Commit 767a105"},{"last_affected":"Master Commit 767a105"},{"introduced":"Master Commit 767a105"},{"last_affected":"Master Commit 767a105"},{"introduced":"Master Commit 767a105"},{"last_affected":"Master Commit 767a105"},{"introduced":"Master Commit b1a5500"},{"last_affected":"Master Commit b1a5500"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2022-1594"},{"type":"WEB","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1594"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38072.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38072"},{"type":"FIX","url":"https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/admesh/admesh","events":[{"introduced":"7f22e3fa361db7bb92062d185ecba8e786904f28"},{"fixed":"5fab257268a0ee6f832c18d72af89810a29fbd5f"}],"database_specific":{"cpe":"cpe:2.3:a:admesh_project:admesh:0.98.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.98.4"},{"last_affected":"0.98.4"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.98.4","v0.98.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38072.json","vanir_signatures_modified":"2026-08-12T13:33:09Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"128438977467078069005944980978530379015","length":1969},"id":"CVE-2022-38072-2fd3b084","signature_type":"Function","signature_version":"v1","source":"https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5f","target":{"file":"src/normals.c","function":"stl_fix_normal_directions"}},{"signature_version":"v1","source":"https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5f","target":{"file":"src/normals.c"},"deprecated":false,"digest":{"line_hashes":["29381961251666579836304160910035144137","331296357432087497437842914233706502226","303314701913237536942182058952154523497","149908783363205597030533835287843711044"],"threshold":0.9},"id":"CVE-2022-38072-f7640dd7","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}