Vulnerability CVE-2022-40281


Published: 2022-09-08   Modified: 2022-09-09

Description:
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.

 References:
https://github.com/Samsung/TizenRT/issues/5626
https://www.openssl.org/docs/man1.1.1/man3/SSL_get_peer_certificate.html
https://github.com/Samsung/TizenRT/blob/f8f776dd183246ad8890422c1ee5e8f33ab2aaaf/external/curl/vtls/cyassl.c#L545

Copyright 2026, cxsecurity.com

 

Back to Top