CVE-2022-50009 is a null-pointer dereference vulnerability in the F2FS filesystem module of the Linux kernel, affecting systems utilizing this filesystem. This flaw occurs during atomic write operations when a COW (Copy-On-Write) inode's internal pointer is incorrectly referenced as NULL, leading to a kernel crash. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity and user privileges required. Its primary impact is a denial of service (system crash), with no impact on confidentiality or integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. It is not listed in CISA's Known Exploited Vulnerabilities Catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.8, < 5.18.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.19, < 5.19.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.