CVE Vulnerabilities

CVE-2022-37290

NULL Pointer Dereference

Published: Nov 14, 2022 | Modified: May 01, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
NautilusGnome42.2 (including)42.2 (including)
CajaUbuntubionic*
CajaUbuntufocal*
CajaUbuntukinetic*
CajaUbuntulunar*
CajaUbuntumantic*
CajaUbuntuoracular*
CajaUbuntuplucky*
CajaUbuntuxenial*
NautilusUbuntubionic*
NautilusUbuntudevel*
NautilusUbuntuesm-infra/bionic*
NautilusUbuntuesm-infra/focal*
NautilusUbuntufocal*
NautilusUbuntujammy*
NautilusUbuntukinetic*
NautilusUbuntulunar*
NautilusUbuntumantic*
NautilusUbuntunoble*
NautilusUbuntuoracular*
NautilusUbuntuplucky*
NautilusUbuntuquesting*
NautilusUbuntutrusty*
NautilusUbuntuxenial*
NemoUbuntubionic*
NemoUbuntufocal*
NemoUbuntukinetic*
NemoUbuntulunar*
NemoUbuntumantic*
NemoUbuntuoracular*
NemoUbuntuplucky*
NemoUbuntutrusty*
NemoUbuntuxenial*

Potential Mitigations

References