Vulnerability CVE-2022-40278


Published: 2022-09-29

Description:
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_free after sqlite3_exec, leading to a denial of service.

 References:
https://github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/iotivity/iotivity_1.2-rel/resource/csdk/security/provisioning/src/provisioningdatabasemanager.c#L103
https://github.com/Samsung/TizenRT/issues/5628
https://www.sqlite.org/c3ref/exec.html
https://github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/iotivity/iotivity_1.2-rel/resource/csdk/security/provisioning/src/provisioningdatabasemanager.c#L107
https://www.cve.org/CVERecord?id=CVE-2022-40278

Copyright 2026, cxsecurity.com

 

Back to Top