CVE Vulnerabilities

CVE-2022-41860

NULL Pointer Dereference

Published: Jan 17, 2023 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FreeradiusFreeradius0.9.3 (including)3.0.25 (including)
Red Hat Enterprise Linux 8RedHatfreeradius:3.0-8080020221214103624.89170a74*
Red Hat Enterprise Linux 9RedHatfreeradius-0:3.0.21-37.el9*
FreeradiusUbuntubionic*
FreeradiusUbuntuesm-infra/bionic*
FreeradiusUbuntuesm-infra/focal*
FreeradiusUbuntuesm-infra/xenial*
FreeradiusUbuntufocal*
FreeradiusUbuntutrusty*
FreeradiusUbuntuxenial*

Potential Mitigations

References