CVE-2022-28070: Null Pointer Dereference
Published Aug 22, 2023
·Updated
A null pointer deference in coreanalfcn function in radare2 5.4.2 and 5.4.0.
Affected Software
2 affected components
Radare Radare2=5.4.0
Radare Radare2=5.4.2
Remediation
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-28070?
CVE-2022-28070 refers to a null pointer deference vulnerability in the __core_anal_fcn function in radare2 versions 5.4.2 and 5.4.0.
2
How severe is CVE-2022-28070?
CVE-2022-28070 has a severity rating of 7.5 (high).
3
Which software versions are affected by CVE-2022-28070?
Radare2 versions 5.4.2 and 5.4.0 are affected by CVE-2022-28070.
4
How can I fix CVE-2022-28070?
To fix CVE-2022-28070, it is recommended to update to a patched version of radare2.
5
Where can I find more information about CVE-2022-28070?
More information about CVE-2022-28070 can be found at the following reference link: https://github.com/radareorg/radare2/commit/4aff1bb00224de4f5bc118f987dfd5d2fe3450d0