{"id":"CVE-2022-47021","details":"A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.","modified":"2026-08-12T13:01:23.554698Z","published":"2023-01-20T00:00:00Z","related":["openSUSE-SU-2024:0013-1","openSUSE-SU-2024:12799-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/47xxx/CVE-2022-47021.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/47xxx/CVE-2022-47021.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ODIA6QRIRBNF2HRXOE5VCZ2AFP4ZB4R/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4LIKBLOE433RA44YTYUZLED4IOWJG5DV/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ED4CWLBR2WQ2IXXTHZ24UYZBRNCLMJXH/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYPAQANM2ZNPXRBFOS5NFXNJ7O4Q3OBD/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-47021"},{"type":"REPORT","url":"https://github.com/xiph/opusfile/issues/36"},{"type":"FIX","url":"https://github.com/xiph/opusfile/commit/0a4cd796df5b030cb866f3f4a5e41a4b92caddf5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xiph/opusfile","events":[{"introduced":"2c239ebc90d6c105c52b266ad4664a76a4cc2261"},{"fixed":"0a4cd796df5b030cb866f3f4a5e41a4b92caddf5"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:xiph:opusfile:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9"},{"last_affected":"0.12"}]}}],"versions":["v0.12","v0.11","v0.10","v0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47021.json","vanir_signatures_modified":"2026-08-12T13:01:23Z","vanir_signatures":[{"id":"CVE-2022-47021-16c8be16","signature_type":"Line","signature_version":"v1","source":"https://github.com/xiph/opusfile/commit/0a4cd796df5b030cb866f3f4a5e41a4b92caddf5","target":{"file":"src/opusfile.c"},"deprecated":false,"digest":{"line_hashes":["130767672307147289407420356559775706029","13317614848687912484193478925602636191","144553095702598871125400013378138582395","200013815770376048462406562066036482636","139408764762257582073874266626380380189","269018161722186257905673236517628259590","128948526805784082996200560188643188646","20540233520340268411095201284128365705"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/xiph/opusfile/commit/0a4cd796df5b030cb866f3f4a5e41a4b92caddf5","target":{"function":"op_get_data","file":"src/opusfile.c"},"deprecated":false,"digest":{"function_hash":"303514918919810935869497108359724706223","length":369},"id":"CVE-2022-47021-3d679de0"},{"target":{"file":"src/opusfile.c","function":"op_open1"},"deprecated":false,"digest":{"function_hash":"168853061540030313505212027813007375267","length":1831},"id":"CVE-2022-47021-491ab479","signature_type":"Function","signature_version":"v1","source":"https://github.com/xiph/opusfile/commit/0a4cd796df5b030cb866f3f4a5e41a4b92caddf5"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}