CVE-2022-0546: Blender

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.

Affected products

  • Blender Blender: version 2.93.8 only; version 3.0 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only; version 11.0 only
  • Fedoraproject Extra Packages For Enterprise Linux: version 7.0 only
  • Fedoraproject Fedora: version 34 only

Published 2022-02-24. Last modified 2026-06-17.