CVE Vulnerabilities

CVE-2022-31681

NULL Pointer Dereference

Published: Oct 07, 2022 | Modified: Oct 11, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Cloud_foundation Vmware 4.2 (including) 4.3.1.1 (excluding)
Cloud_foundation Vmware 4.4 (including) 4.4 (including)
Cloud_foundation Vmware 4.4.1 (including) 4.4.1 (including)
Cloud_foundation Vmware 4.4.1.1 (including) 4.4.1.1 (including)
Esxi Vmware * 7.0 (excluding)
Esxi Vmware 7.0 (including) 7.0 (including)
Esxi Vmware 7.0-beta (including) 7.0-beta (including)
Esxi Vmware 7.0-update_1 (including) 7.0-update_1 (including)
Esxi Vmware 7.0-update_1a (including) 7.0-update_1a (including)
Esxi Vmware 7.0-update_1b (including) 7.0-update_1b (including)
Esxi Vmware 7.0-update_1c (including) 7.0-update_1c (including)
Esxi Vmware 7.0-update_1d (including) 7.0-update_1d (including)
Esxi Vmware 7.0-update_1e (including) 7.0-update_1e (including)
Esxi Vmware 7.0-update_2 (including) 7.0-update_2 (including)
Esxi Vmware 7.0-update_2a (including) 7.0-update_2a (including)
Esxi Vmware 7.0-update_2c (including) 7.0-update_2c (including)
Esxi Vmware 7.0-update_2d (including) 7.0-update_2d (including)
Esxi Vmware 7.0-update_2e (including) 7.0-update_2e (including)
Esxi Vmware 7.0-update_3c (including) 7.0-update_3c (including)
Esxi Vmware 7.0-update_3d (including) 7.0-update_3d (including)
Esxi Vmware 7.0-update_3e (including) 7.0-update_3e (including)

Potential Mitigations

References