CVE-2022-39837: Null Pointer Dereference
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointer dereference,
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-39837?
CVE-2022-39837 is a vulnerability discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through version 2.18.8.
What is the severity of CVE-2022-39837?
CVE-2022-39837 has a severity rating of medium with a CVSS score of 5.5.
How does CVE-2022-39837 impact the affected software?
CVE-2022-39837 allows an attacker to create a crafted DLT file that crashes the process due to a faulty DLT file parser and missing validation checks, leading to a NULL pointer dereference.
Is there a fix available for CVE-2022-39837?
At the time of writing, there is no known fix or patch available for CVE-2022-39837. It is recommended to follow the vendor's advisory and apply any updates or mitigation measures as they become available.
Where can I find more information about CVE-2022-39837?
You can find more information about CVE-2022-39837 in the following references: [1] [2].