High severity7.5NVD Advisory· Published Sep 8, 2022· Updated Jun 17, 2026
CVE-2022-40281
CVE-2022-40281
Description
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:samsung:tizenrt:1.0:m1:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:samsung:tizenrt:1.0:m1:*:*:*:*:*:*
- cpe:2.3:o:samsung:tizenrt:1.1:-:*:*:*:*:*:*
- cpe:2.3:o:samsung:tizenrt:2.0:-:*:*:*:*:*:*
- cpe:2.3:o:samsung:tizenrt:3.0:gbm:*:*:*:*:*:*
- (no CPE)range: <=3.0_GBM, 3.1_PRE
- Samsung/TizenRTdescription
Patches
Vulnerability mechanics
References
3- github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/curl/vtls/cyassl.cnvdThird Party Advisory
- github.com/Samsung/TizenRT/issues/5626nvdIssue TrackingThird Party Advisory
- www.openssl.org/docs/man1.1.1/man3/SSL_get_peer_certificate.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.