CVE-2022-50432 is a use-after-free vulnerability in the Linux kernel's kernfs component, specifically in the __kernfs_remove function. This flaw can be triggered by concurrent calls to kernfs_remove_by_name_ns() for the same file, leading to system instability. It affects the Linux kernel. The vulnerability has a CVSSv3.1 score of 7.8 (High), indicating a significant risk. It is a local attack (AV:L) with low attack complexity (AC:L) and requires low privileges (PR:L). Successful exploitation could lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.14, < 4.9.332CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.298CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.264CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.223CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.153CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.