CVE-2022-1649
published 2022-05-10CVE-2022-1649: Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.70%
49.4th percentile
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.9.0+dfsg-1 (sid) | radare2 5.9.0+dfsg-1 (sid) |
| radare | radare2 | < 5.7.0 | 5.7.0 |
| radareorg | radareorg_radare2 | >= unspecified < 5.7.0 | 5.7.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-1649: radare2 - Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 i...
vendor_debian·2022·CVSS 5.5
CVE-2022-1649 [MEDIUM] CVE-2022-1649: radare2 - Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 i...
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
Scope: local
sid: resolved (fixed in 5.9.0+dfsg-1)
GHSA
GHSA-gvc2-c45p-m2r9: Null pointer dereference in libr/bin/format/mach0/mach0
ghsa_unreviewed·2022-05-11
CVE-2022-1649 [MEDIUM] CWE-476 GHSA-gvc2-c45p-m2r9: Null pointer dereference in libr/bin/format/mach0/mach0
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
OSV
CVE-2022-1649: Null pointer dereference in libr/bin/format/mach0/mach0
osv·2022-05-10·CVSS 5.5
CVE-2022-1649 [MEDIUM] CVE-2022-1649: Null pointer dereference in libr/bin/format/mach0/mach0
Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Callback Technologies CBFS Filter denial-of-service vulnerabilities
blogs_talos·2022-11-22·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Callback Technologies CBFS Filter denial-of-service vulnerabilities
## Vulnerability Spotlight: Callback Technologies CBFS Filter denial-of-service vulnerabilities
Cisco Talos recently discovered three denial-of-service vulnerabilities in Callback Technologies CBFS Filter.
Callback Technologies has a CBFS file storage solution for use in customizing data persistence on devices. To accompany this, their CBFS Filter manages this file storage solution, allowing users to create filter and access rules, modify and encrypt data, etc.
Talos has identified three null pointer dereference vulnerabilities in CBFS Filter:
TALOS-2022-1647 (CVE-2022-43588)
TALOS-2022-1648 (CVE-2022-43589)
TALOS-2022-1649 (CVE-2022-43590)
A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger these vulnerabilities.
Ci
Talos
Vulnerability Spotlight: Callback Technologies CBFS Filter denial-of-service vulnerabilities
blogs_talos·2022-11-22·CVSS 5.5
CVE-2022-43588 [MEDIUM] Vulnerability Spotlight: Callback Technologies CBFS Filter denial-of-service vulnerabilities
Cisco Talos recently discovered three denial-of-service vulnerabilities in Callback Technologies CBFS Filter.
Callback Technologies has a CBFS file storage solution for use in customizing data persistence on devices. To accompany this, their CBFS Filter manages this file storage solution, allowing users to create filter and access rules, modify and encrypt data, etc.
Talos has identified three null pointer dereference vulnerabilities in CBFS Filter:
TALOS-2022-1647 (CVE-2022-43588)
TALOS-2022-1648 (CVE-2022-43589)
TALOS-2022-1649 (CVE-2022-43590)
A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger these vulnerabilities.
Cisco Talos worked with Callback Technologies to ensure that these issues were resolved and an upda
2022-05-10
Published