CVE-2022-50002 is a NULL pointer dereference vulnerability in the Linux kernel's mlx5 network driver, specifically affecting the LAG (Link Aggregation Group) functionality. It occurs when the MLX5_LAG_FLAG_NDEVS_READY flag is incorrectly set, leading to a scenario where one of the two expected network devices is not fully registered, but the system believes both are ready. This can result in a kernel crash when the mlx5_do_bond() function attempts to access an invalid pointer. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges to trigger. The primary impact is a high availability risk, as it can lead to a denial of service due to the kernel panic. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.14, < 5.19.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.