CWE-476 — NULL Pointer Dereference
CWE-476: NULL Pointer Dereference
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Base |
| Status | Stable |
| Likelihood of exploit | Medium |
Description
The product dereferences a pointer that it expects to be valid but is NULL.
Common consequences
- Availability: DoS: Crash, Exit, or Restart
- Integrity, Confidentiality: Execute Unauthorized Code or Commands, Read Memory, Modify Memory
Mitigations
Implementation — For any pointers that could have been modified or provided from a function that can return NULL, check the pointer for NULL before use. When working with a multithreaded or otherwise asynchronous environment, ensure that proper locking APIs are used to lock before the check, and unlock when it has finished [REF-1484].
Requirements — Select a programming language that is not susceptible to these issues.
Implementation — Check the results of all functions that return a value and verify that the value is non-null before acting upon it.
Architecture and Design — Identify all variables and data stores that receive information from external sources, and apply input validation to make sure that they are only initialized to expected values.
Implementation — Explicitly initialize all variables and other data stores, either during declaration or just before the first usage.
References
- CWE page: https://cwe.mitre.org/data/definitions/476.html
- CWE list: https://cwe.mitre.org/data/index.html