Umbra Wiki weakness weakness/CWE-476
Back to wiki

CWE-476 — NULL Pointer Dereference

provenance: imported · CWE: CWE-476

CWE-476: NULL Pointer Dereference

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Stable
Likelihood of exploit Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Common consequences

  • Availability: DoS: Crash, Exit, or Restart
  • Integrity, Confidentiality: Execute Unauthorized Code or Commands, Read Memory, Modify Memory

Mitigations

Implementation — For any pointers that could have been modified or provided from a function that can return NULL, check the pointer for NULL before use. When working with a multithreaded or otherwise asynchronous environment, ensure that proper locking APIs are used to lock before the check, and unlock when it has finished [REF-1484].

Requirements — Select a programming language that is not susceptible to these issues.

Implementation — Check the results of all functions that return a value and verify that the value is non-null before acting upon it.

Architecture and Design — Identify all variables and data stores that receive information from external sources, and apply input validation to make sure that they are only initialized to expected values.

Implementation — Explicitly initialize all variables and other data stores, either during declaration or just before the first usage.

References

  • CWE page: https://cwe.mitre.org/data/definitions/476.html
  • CWE list: https://cwe.mitre.org/data/index.html