CVE-2022-50442 is an out-of-bounds read vulnerability in the Linux kernel's NTFS3 file system driver. Specifically, it occurs during the parsing of index buffers in NTFS directory operations due to insufficient validation of the returned buffer length. This flaw could lead to out-of-bounds memory access. Rated with a CVSS score of 7.1 (High), this vulnerability has a local attack vector and low attack complexity, meaning an attacker with local user privileges could trigger it. The primary impact is a high availability impact, potentially leading to system crashes or denial of service. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or immediate concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15, < 5.15.87CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.0.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1, < 6.1.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.