CVE-2022-41860
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
17/01/2023
Last modified:
03/11/2025
Description
In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:freeradius:freeradius:*:*:*:*:*:*:*:* | 0.9.3 (including) | 3.0.25 (including) |
To consult the complete list of CPE names with products and versions, see this page



