CVE-2022-50563 is a use-after-free (UAF) vulnerability in the Linux kernel's device mapper (dm) thin provisioning module. Specifically, it occurs when dm_resume() and dm_destroy() operations are executed concurrently, leading to a race condition where a timer is added by dm_resume() but not cancelled by dm_destroy() due to the suspended status. This results in the timer attempting to access freed memory when it eventually fires. The vulnerability has no assigned CVSS score, but its FAUCET Risk Score is 5/100, indicating a low to moderate severity. The attack vector involves a race condition during specific device mapper operations, and the potential impact is a system crash (kernel panic) due to the UAF, leading to denial of service. There is no evidence of active exploitation, exploit code availability (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in CISA's Known Exploited Vulnerabilities Catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 3.2CNA affecteddefault affected | |
| Linux | Linux | >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 34cd15d83b7206188d440b29b68084fcafde9395, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 34fe9c2251f19786a6689149a6212c6c0de1d63b, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 550a4fac7ecfee5bac6a0dd772456ca62fb72f46, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 7ae6aa649394e1e7f6dafb55ce0d578c0572a280, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 7ee059d06a5d3c15465959e0472993e80fbe4e81, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 88430ebcbc0ec637b710b947738839848c20feff, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 94e231c9d6f2648d2f1f68e7f476e050ee0a6159, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < d9971fa4d8bde63d49c743c1b32d12fbbd3a30bd, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < e8b8e0d2bbf7d1172c4f435621418e29ee408d46CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.