CVE-2022-1507: Chafa Project Chafa
Medium severity, CVSS 5.5. EPSS: 0.9% chance of exploitation in the next 30 days.
chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.
Affected products
- Chafa Project Chafa: before 1.10.2 (fixed in 1.10.2)
- Fedoraproject Fedora: version 34 only; version 35 only; version 36 only
Published 2022-04-27. Last modified 2026-06-17.