High severity7.5NVD Advisory· Published Sep 5, 2022· Updated Jun 17, 2026
CVE-2022-39829
CVE-2022-39829
Description
There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:samsung:mtower:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:samsung:mtower:*:*:*:*:*:*:*:*range: <=0.3.0
- (no CPE)
- (no CPE)range: <=0.3.0
Patches
Vulnerability mechanics
References
3- github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tools/ecdsa_keygen.cnvdExploitThird Party Advisory
- github.com/Samsung/mTower/issues/75nvdExploitIssue TrackingThird Party Advisory
- www.openssl.org/docs/manmaster/man3/EVP_CIPHER_CTX_new.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.