CVE-2022-36227 - CVE House
Back to Database
Status published Critical CVE-2022-36227

In libarchive before 3.6.2, the software does not check for...

Vulnerability Description

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-36227

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

libarchive, debian linux, fedora, universal forwarder
Vulnerable Versions:
3.0.0, 10.0, 37, 8.2.0, 9.0.0, 9.1.0

Timeline

Official Publish: November 22nd, 2022
Last Modified: November 3rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.