CVE-2022-50433 is a use-after-free vulnerability in the Linux kernel's EFI subsystem, specifically related to how ACPI tables (SSDTs) are loaded from variables. The flaw, introduced by a prior commit, causes memory to be unconditionally freed even when the ACPI table successfully loads, leading to KASAN errors. This vulnerability affects Linux kernel versions where the problematic commit was integrated. The vulnerability is rated 7.8 HIGH on the CVSS scale, indicating a significant risk. An attacker with local privileges (PR:L) could exploit this with low attack complexity (AC:L) to achieve high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). The attack vector is local (AV:L), meaning direct access to the affected system is required. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, < 6.0.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.