CVE-2022-0544: Blender

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.

Affected products

  • Blender Blender: before 2.83.19 (fixed in 2.83.19); from 2.90.0, before 2.93.8 (fixed in 2.93.8); from 3.0, before 3.1 (fixed in 3.1)
  • Debian Debian Linux: version 9.0 only; version 10.0 only

Published 2022-02-24. Last modified 2026-06-17.