CWE-252
AllowedUnchecked Return Value
Abstraction: Base · Status: Draft
The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
256 vulnerabilities reference this CWE, most recent first.
GHSA-9X54-G48C-7W9W
Vulnerability from github – Published: 2022-09-30 00:00 – Updated: 2022-10-01 00:00An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/src/l2_packet/l2_packet_pcap.c has a missing check on the return value of pcap_dispatch, leading to a denial of service (malfunction).
{
"affected": [],
"aliases": [
"CVE-2022-40279"
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-29T03:15:00Z",
"severity": "HIGH"
},
"details": "An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/src/l2_packet/l2_packet_pcap.c has a missing check on the return value of pcap_dispatch, leading to a denial of service (malfunction).",
"id": "GHSA-9x54-g48c-7w9w",
"modified": "2022-10-01T00:00:17Z",
"published": "2022-09-30T00:00:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40279"
},
{
"type": "WEB",
"url": "https://github.com/Samsung/TizenRT/issues/5629"
},
{
"type": "WEB",
"url": "https://github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/wpa_supplicant/src/l2_packet/l2_packet_pcap.c#L181"
},
{
"type": "WEB",
"url": "https://linux.die.net/man/3/pcap_dispatch"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-C3CJ-4XXG-MG34
Vulnerability from github – Published: 2022-09-25 00:00 – Updated: 2022-09-27 00:00An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.
{
"affected": [],
"aliases": [
"CVE-2022-38936"
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-09-23T11:15:00Z",
"severity": "HIGH"
},
"details": "An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.",
"id": "GHSA-c3cj-4xxg-mg34",
"modified": "2022-09-27T00:00:18Z",
"published": "2022-09-25T00:00:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38936"
},
{
"type": "WEB",
"url": "https://github.com/cloudwu/pbc/issues/158"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-C7XG-CC4Q-797M
Vulnerability from github – Published: 2022-05-13 01:40 – Updated: 2022-05-13 01:40A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.
{
"affected": [],
"aliases": [
"CVE-2017-0774"
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-09-08T20:29:00Z",
"severity": "HIGH"
},
"details": "A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.",
"id": "GHSA-c7xg-cc4q-797m",
"modified": "2022-05-13T01:40:40Z",
"published": "2022-05-13T01:40:40Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-0774"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2017-09-01"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/100649"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-C9G6-7M2J-RFH8
Vulnerability from github – Published: 2022-11-02 12:00 – Updated: 2022-11-03 19:00A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212660.
{
"affected": [],
"aliases": [
"CVE-2022-3807"
],
"database_specific": {
"cwe_ids": [
"CWE-252",
"CWE-400",
"CWE-404"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-11-01T20:15:00Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212660.",
"id": "GHSA-c9g6-7m2j-rfh8",
"modified": "2022-11-03T19:00:27Z",
"published": "2022-11-02T12:00:43Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3807"
},
{
"type": "WEB",
"url": "https://github.com/axiomatic-systems/Bento4/issues/803"
},
{
"type": "WEB",
"url": "https://github.com/axiomatic-systems/Bento4/files/9820612/mp42aac_exhaustive_AP4_RtpAtom50.zip"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.212660"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-CFV5-3VM4-4JFP
Vulnerability from github – Published: 2022-08-29 20:06 – Updated: 2022-09-02 00:01A flaw was found in the copying tool nbdcopy of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.
{
"affected": [],
"aliases": [
"CVE-2022-0485"
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-08-29T15:15:00Z",
"severity": "HIGH"
},
"details": "A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.",
"id": "GHSA-cfv5-3vm4-4jfp",
"modified": "2022-09-02T00:01:03Z",
"published": "2022-08-29T20:06:49Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0485"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2022-0485"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2046194"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2050324"
},
{
"type": "WEB",
"url": "https://gitlab.com/nbdkit/libnbd/-/commit/8d444b41d09a700c7ee6f9182a649f3f2d325abb"
},
{
"type": "WEB",
"url": "https://listman.redhat.com/archives/libguestfs/2022-February/msg00104.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-CG3G-C98G-38CG
Vulnerability from github – Published: 2022-05-01 18:17 – Updated: 2024-10-15 18:30Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
{
"affected": [],
"aliases": [
"CVE-2007-3798"
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2007-07-16T22:30:00Z",
"severity": "MODERATE"
},
"details": "Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.",
"id": "GHSA-cg3g-c98g-38cg",
"modified": "2024-10-15T18:30:48Z",
"published": "2022-05-01T18:17:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2007-3798"
},
{
"type": "WEB",
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9771"
},
{
"type": "WEB",
"url": "http://bugs.gentoo.org/show_bug.cgi?id=184815"
},
{
"type": "WEB",
"url": "http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-bgp.c?r1=1.91.2.11\u0026r2=1.91.2.12"
},
{
"type": "WEB",
"url": "http://docs.info.apple.com/article.html?artnum=307179"
},
{
"type": "WEB",
"url": "http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26135"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26168"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26223"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26231"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26263"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26266"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26286"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26395"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26404"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26521"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/27580"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/28136"
},
{
"type": "WEB",
"url": "http://security.freebsd.org/advisories/FreeBSD-SA-07:06.tcpdump.asc"
},
{
"type": "WEB",
"url": "http://security.gentoo.org/glsa/glsa-200707-14.xml"
},
{
"type": "WEB",
"url": "http://slackware.com/security/viewer.php?l=slackware-security\u0026y=2007\u0026m=slackware-security.449313"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2007/dsa-1353"
},
{
"type": "WEB",
"url": "http://www.digit-labs.org/files/exploits/private/tcpdump-bgp.c"
},
{
"type": "WEB",
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:148"
},
{
"type": "WEB",
"url": "http://www.novell.com/linux/security/advisories/2007_16_sr.html"
},
{
"type": "WEB",
"url": "http://www.redhat.com/support/errata/RHSA-2007-0368.html"
},
{
"type": "WEB",
"url": "http://www.redhat.com/support/errata/RHSA-2007-0387.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/archive/1/474225/100/0/threaded"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/24965"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1018434"
},
{
"type": "WEB",
"url": "http://www.trustix.org/errata/2007/0023"
},
{
"type": "WEB",
"url": "http://www.turbolinux.com/security/2007/TLSA-2007-46.txt"
},
{
"type": "WEB",
"url": "http://www.ubuntu.com/usn/usn-492-1"
},
{
"type": "WEB",
"url": "http://www.us-cert.gov/cas/techalerts/TA07-352A.html"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2007/2578"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2007/4238"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-CQ7M-PX5H-48PX
Vulnerability from github – Published: 2025-10-15 18:31 – Updated: 2025-10-15 18:31When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
{
"affected": [],
"aliases": [
"CVE-2025-61935"
],
"database_specific": {
"cwe_ids": [
"CWE-252"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-10-15T16:15:35Z",
"severity": "HIGH"
},
"details": "When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.\u00a0\u00a0Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
"id": "GHSA-cq7m-px5h-48px",
"modified": "2025-10-15T18:31:51Z",
"published": "2025-10-15T18:31:51Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61935"
},
{
"type": "WEB",
"url": "https://my.f5.com/manage/s/article/K000154664"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-CW7V-45WM-MCF2
Vulnerability from github – Published: 2026-03-27 22:21 – Updated: 2026-04-30 18:33Duplicate Advisory
This advisory has been withdrawn because it is been determined to not be a vulnerability. This link is maintained to preserve external references.
Original Description
Summary
Kirby CMS through version 5.1.4 allows an authenticated user with Editor permissions to cause a persistent Denial of Service (DoS) via a malformed image upload.
Details
The vulnerability is caused by improper validation of the return value of PHP's getimagesize() function. When a malformed file is uploaded with a valid image extension (e.g., .jpg), the function returns false instead of an expected array.
The application fails to handle this condition properly and proceeds with image processing, resulting in a fatal TypeError. This leads to persistent application crashes when the affected file is accessed.
Impact
- Persistent Denial of Service (DoS)
- Affected pages return HTTP 500 errors
- Requires manual removal of the malformed file to restore functionality
- Exploitable by authenticated users with Editor permissions
Identifiers
- CVE-2026-29905
Resources
- https://github.com/github/advisory-database/pull/7503
- https://github.com/Stalin-143/CVE-2026-29905
- https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1
- https://www.cve.org/CVERecord?id=CVE-2026-29905
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "getkirby/cms"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.2.0-rc.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-29905"
],
"database_specific": {
"cwe_ids": [
"CWE-20",
"CWE-252"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-27T22:21:26Z",
"nvd_published_at": "2026-03-26T17:16:34Z",
"severity": "MODERATE"
},
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is been determined to not be a vulnerability. This link is maintained to preserve external references.\n\n### Original Description\n\n## Summary\n\nKirby CMS through version 5.1.4 allows an authenticated user with Editor permissions to cause a persistent Denial of Service (DoS) via a malformed image upload.\n\n## Details\n\nThe vulnerability is caused by improper validation of the return value of PHP\u0027s `getimagesize()` function. When a malformed file is uploaded with a valid image extension (e.g., `.jpg`), the function returns `false` instead of an expected array.\n\nThe application fails to handle this condition properly and proceeds with image processing, resulting in a fatal `TypeError`. This leads to persistent application crashes when the affected file is accessed.\n\n## Impact\n\n- Persistent Denial of Service (DoS)\n- Affected pages return HTTP 500 errors\n- Requires manual removal of the malformed file to restore functionality\n- Exploitable by authenticated users with Editor permissions\n\n\n## Identifiers\n- CVE-2026-29905\n\n## Resources\n\n- https://github.com/github/advisory-database/pull/7503\n- https://github.com/Stalin-143/CVE-2026-29905\n- https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1\n- https://www.cve.org/CVERecord?id=CVE-2026-29905",
"id": "GHSA-cw7v-45wm-mcf2",
"modified": "2026-04-30T18:33:03Z",
"published": "2026-03-27T22:21:26Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/Stalin-143/CVE-2026-29905/security/advisories/GHSA-cw7v-45wm-mcf2"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29905"
},
{
"type": "WEB",
"url": "https://github.com/github/advisory-database/pull/7503"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/1MwvvSYIwnC8kOIzjycGMQZw4d2K2ef8h/view?usp=sharing"
},
{
"type": "PACKAGE",
"url": "https://github.com/Stalin-143/CVE-2026-29905"
},
{
"type": "WEB",
"url": "https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload",
"withdrawn": "2026-04-30T18:33:03Z"
}
GHSA-CXVJ-JX5H-9XF2
Vulnerability from github – Published: 2022-10-18 12:00 – Updated: 2022-10-18 12:00An Unchecked Return Value to NULL Pointer Dereference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series if Unified Threat Management (UTM) Enhanced Content Filtering (CF) and AntiVirus (AV) are enabled together and the system processes specific valid transit traffic the Packet Forwarding Engine (PFE) will crash and restart. This issue affects Juniper Networks Junos OS 21.4 versions prior to 21.4R1-S2, 21.4R2 on SRX Series. This issue does not affect Juniper Networks Junos OS versions prior to 21.4R1.
{
"affected": [],
"aliases": [
"CVE-2022-22231"
],
"database_specific": {
"cwe_ids": [
"CWE-252",
"CWE-476",
"CWE-690"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-10-18T03:15:00Z",
"severity": "HIGH"
},
"details": "An Unchecked Return Value to NULL Pointer Dereference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series if Unified Threat Management (UTM) Enhanced Content Filtering (CF) and AntiVirus (AV) are enabled together and the system processes specific valid transit traffic the Packet Forwarding Engine (PFE) will crash and restart. This issue affects Juniper Networks Junos OS 21.4 versions prior to 21.4R1-S2, 21.4R2 on SRX Series. This issue does not affect Juniper Networks Junos OS versions prior to 21.4R1.",
"id": "GHSA-cxvj-jx5h-9xf2",
"modified": "2022-10-18T12:00:30Z",
"published": "2022-10-18T12:00:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22231"
},
{
"type": "WEB",
"url": "https://kb.juniper.net/JSA69885"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-F329-HQH6-8QMX
Vulnerability from github – Published: 2022-10-18 12:00 – Updated: 2022-10-21 19:01An Unchecked Return Value to NULL Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). In Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario, configured with Segment Routing Mapping Server (SRMS) at any node, when an Area Border Router (ABR) leaks the SRMS entries having "S" flag set from IS-IS Level 2 to Level 1, an rpd core might be observed when a specific low privileged CLI command is issued. This issue affects: Juniper Networks Junos OS 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R2. Juniper Networks Junos OS Evolved 21.4-EVO versions prior to 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO; 22.1-EVO versions prior to 22.1R2-EVO. This issue does not affect: Juniper Networks Junos OS versions prior to 21.4R1. Juniper Networks Junos OS Evolved versions prior to 21.4R1-EVO.
{
"affected": [],
"aliases": [
"CVE-2022-22233"
],
"database_specific": {
"cwe_ids": [
"CWE-252",
"CWE-476",
"CWE-690"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-10-18T03:15:00Z",
"severity": "MODERATE"
},
"details": "An Unchecked Return Value to NULL Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). In Segment Routing (SR) to Label Distribution Protocol (LDP) interworking scenario, configured with Segment Routing Mapping Server (SRMS) at any node, when an Area Border Router (ABR) leaks the SRMS entries having \"S\" flag set from IS-IS Level 2 to Level 1, an rpd core might be observed when a specific low privileged CLI command is issued. This issue affects: Juniper Networks Junos OS 21.4 versions prior to 21.4R1-S2, 21.4R2-S1, 21.4R3; 22.1 versions prior to 22.1R2. Juniper Networks Junos OS Evolved 21.4-EVO versions prior to 21.4R1-S2-EVO, 21.4R2-S1-EVO, 21.4R3-EVO; 22.1-EVO versions prior to 22.1R2-EVO. This issue does not affect: Juniper Networks Junos OS versions prior to 21.4R1. Juniper Networks Junos OS Evolved versions prior to 21.4R1-EVO.",
"id": "GHSA-f329-hqh6-8qmx",
"modified": "2022-10-21T19:01:13Z",
"published": "2022-10-18T12:00:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22233"
},
{
"type": "WEB",
"url": "https://kb.juniper.net/JSA69887"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
Mitigation MIT-53
Check the results of all functions that return a value and verify that the value is expected.
Mitigation MIT-56
For any pointers that could have been modified or provided from a function that can return NULL, check the pointer for NULL before use. When working with a multithreaded or otherwise asynchronous environment, ensure that proper locking APIs are used to lock before the check, and unlock when it has finished [REF-1484].
Mitigation
Ensure that you account for all possible return values from the function.
Mitigation
When designing a function, make sure you return a value or throw an exception in case of an error.
No CAPEC attack patterns related to this CWE.