Candidate: CVE-2022-1249 PublicDate: 2022-04-29 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1249 https://github.com/rhboot/pesign/pull/79 Description: A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function fails to handle the NULL pwdata invocation from daemon.c, which leads to an explicit NULL dereference and crash on all attempts to daemonize pesign. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_pesign: upstream_pesign: not-affected (debian: Vulnerable code introduced later) trusty_pesign: ignored (out of standard support) xenial_pesign: ignored (out of standard support) bionic_pesign: needs-triage focal_pesign: needs-triage impish_pesign: needs-triage jammy_pesign: needs-triage devel_pesign: needs-triage