CVE Vulnerabilities

CVE-2022-28070

NULL Pointer Dereference

Published: Aug 22, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Radare2 Radare 5.4.0 (including) 5.4.0 (including)
Radare2 Radare 5.4.2 (including) 5.4.2 (including)
Radare2 Ubuntu bionic *
Radare2 Ubuntu focal *
Radare2 Ubuntu lunar *
Radare2 Ubuntu mantic *
Radare2 Ubuntu oracular *
Radare2 Ubuntu trusty *
Radare2 Ubuntu xenial *

Potential Mitigations

References