Skip to content

[GHSA-wj94-fvj2-f29x] Add finder credit and Ubuntu USN reference (CVE-2022-0529) - #9649

Open
ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9649from
ByteHackr:cve-2022-0529-credit-GHSA-wj94-fvj2-f29x
Open

ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9649from
ByteHackr:cve-2022-0529-credit-GHSA-wj94-fvj2-f29x

Conversation

@ByteHackr

Copy link
Copy Markdown

Adds a credits entry crediting Sandipan Roy (@ByteHackr) as FINDER for this advisory, and adds the CVE record JSON as a supporting WEB reference.

Public evidence supporting this credit:

  • Red Hat Bugzilla #2051402 (CVE-2022-0529, alias of the bug) was created by Sandipan Roy — per the Bugzilla REST API (creator field: "Sandipan Roy", account saroy), who reported the heap out-of-bound write issue in unzip 6.0
  • The advisory already references the proof-of-concept published by the reporter: https://github.com/ByteHackr/unzip_poc

The credits structure follows the OSV schema and the convention already used in this repository (e.g. merged PR #7190 and open PR #9446).

Per CONTRIBUTING.md this PR touches exactly one advisory.

@github-actions
github-actions Bot changed the base branch from main to ByteHackr/advisory-improvement-9649 September 20, 2026 19:04
@ByteHackr

Copy link
Copy Markdown
Author

Thanks! Aside from the credit, would the curation team be able to consider this advisory for review (i.e., upgrade it from the NVD mirror entry to a reviewed advisory)? It affects a system/distro package (unzip), so I understand ecosystem version-range mapping may be limited, but happy to help with any additional information (affected versions, fixed versions, references) that makes the review possible.

@ByteHackr
ByteHackr force-pushed the cve-2022-0529-credit-GHSA-wj94-fvj2-f29x branch from 61e08fa to df60fbe Compare September 20, 2026 20:12
@ByteHackr ByteHackr changed the title Add finder credit for GHSA-wj94-fvj2-f29x [GHSA-wj94-fvj2-f29x] Add finder credit and Ubuntu USN reference (CVE-2022-0529) Sep 20, 2026
@ByteHackr

Copy link
Copy Markdown
Author

Added the Ubuntu USN-5673-1 reference (covers this CVE). Note on affected: intentionally left empty — unzip is a C-level OS package outside the supported ecosystems and upstream Info-ZIP has not shipped a fix. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant