CVE-2022-50374 describes a NULL pointer dereference vulnerability in the Linux kernel's Bluetooth HCI UART driver, specifically affecting the hci_uart_tty_close() function. This flaw arises from improper handling of percpu_init_rwsem() failures during device registration and opening, impacting the Linux kernel. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a local attack vector with low attack complexity, requiring local privileges. Successful exploitation could lead to a denial-of-service (DoS) condition, causing system instability or crashes. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14.63, < 4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.14.63, < 5.10.150CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.75CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.19.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.