CVE Vulnerabilities

CVE-2022-0240

NULL Pointer Dereference

Published: Jan 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

mruby is vulnerable to NULL Pointer Dereference

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
MrubyMruby*3.2 (excluding)
CargoUbuntubionic*
CargoUbuntuimpish*
CargoUbuntukinetic*
CargoUbuntutrusty*
CargoUbuntuxenial*
GroongaUbuntubionic*
GroongaUbuntufocal*
GroongaUbuntuimpish*
GroongaUbuntukinetic*
GroongaUbuntulunar*
GroongaUbuntumantic*
GroongaUbuntuoracular*
GroongaUbuntuplucky*
GroongaUbuntutrusty*
GroongaUbuntuxenial*
H2oUbuntubionic*
H2oUbuntufocal*
H2oUbuntuimpish*
H2oUbuntukinetic*
H2oUbuntulunar*
H2oUbuntumantic*
H2oUbuntuoracular*
H2oUbuntuplucky*
H2oUbuntutrusty*
H2oUbuntuxenial*
MrubyUbuntubionic*
MrubyUbuntufocal*
MrubyUbuntuimpish*
MrubyUbuntukinetic*
MrubyUbuntulunar*
MrubyUbuntumantic*
MrubyUbuntuoracular*
MrubyUbuntuplucky*
MrubyUbuntutrusty*
MrubyUbuntuxenial*
Nghttp2Ubuntubionic*
Nghttp2Ubuntuimpish*
Nghttp2Ubuntutrusty*
Nghttp2Ubuntuxenial*

Potential Mitigations

References