CVE-2022-50008 is a vulnerability in the Linux kernel's kprobes mechanism, specifically affecting the handling of disabled kprobes. The flaw can lead to an infinite loop and system instability, including RCU stalls or soft lockups. This issue arises when the system attempts to disarm an already disabled kprobe, causing a WARN_ONCE() to fire and subsequent cleanup failures. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (denial of service). There is no confidentiality or integrity impact. There is currently no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, < 4.9.327CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.292CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.257CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.212CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.141CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.