CVE Vulnerabilities

CVE-2022-42878

Use of NullPointerException Catch to Detect NULL Pointer Dereference

Published: May 10, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.

Weakness

Catching NullPointerException should not be used as an alternative to programmatic checks to prevent dereferencing a null pointer.

Affected Software

Name Vendor Start Version End Version
Oneapi_hpc_toolkit Intel * 2023.0.0 (excluding)
Trace_analyzer_and_collector Intel * 2021.8.0 (excluding)

Extended Description

Programmers typically catch NullPointerException under three circumstances:

Of these three circumstances, only the last is acceptable.

Potential Mitigations

References