CVE-2022-1382
published 2022-04-18CVE-2022-1382: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the…
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.68%
48.3th percentile
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.9.0+dfsg-1 (sid) | radare2 5.9.0+dfsg-1 (sid) |
| linux | linux_kernel | >= 0 < 4.4.0-253.287 | 4.4.0-253.287 |
| radare | radare2 | < 5.6.8 | 5.6.8 |
| radareorg | radareorg_radare2 | >= unspecified < 5.6.8 | 5.6.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-04-19·CVSS 7.0
CVE-2022-20422 linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that a race condition existed in the instruction emulator
of the Linux kernel on Arm 64-bit systems. A local attacker could use this
to cause a denial of service (system crash). (CVE-2022-20422)
Wei Chen discovered that a race condition existed in the TIPC protocol
implementation in the Linux kernel, leading to a null pointer dereference
vulnerability. A local attacker could use this to cause a denial of service
(system crash). (CVE-2023-1382)
Jose Oliveira and Rodrigo Branco discovered that the Spectre Variant 2
mitigations with prctl syscall were insufficient in some situations. A
local attacker could possibly use this to expose sensitive information.
(CVE-2023-1998)
Daniele Antonioli discovered that the
GHSA
GHSA-q8cr-ff8r-cv2j: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5
ghsa_unreviewed·2022-04-19
CVE-2022-1382 [HIGH] CWE-476 GHSA-q8cr-ff8r-cv2j: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.
OSV
CVE-2022-1382: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5
osv·2022-04-18·CVSS 5.5
CVE-2022-1382 [MEDIUM] CVE-2022-1382: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.
Debian
CVE-2022-1382: radare2 - NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. ...
vendor_debian·2022·CVSS 5.5
CVE-2022-1382 [MEDIUM] CVE-2022-1382: radare2 - NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. ...
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-18
Published