Logo
vulnerabilityCVE-2022-39837
Name
CVE-2022-39837
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointer dereference,
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dlt-daemon
Patched

Vulnerability Ratings#


5.5
CVSSv31
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
3.0.0
Not Affected
yocto
scarthgap
2.18.10
Not Affected

Resolved with patches#


dlt-daemon (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix handle returned value (#384)
Bui Nguyen Quoc Thanh <49302843+thanhbnq@users.noreply.github.com>
CVE-2022-39836
CVE-2022-39837