CVE-2022-50675 is a vulnerability in the Linux kernel's ARM64 MTE (Memory Tagging Extension) implementation. Specifically, it involves an incorrect setting of the PG_mte_tagged flag on pages that were not genuinely MTE-tagged, leading to tag mismatches during page operations like migration. This issue primarily affects systems utilizing ARM64 architecture with MTE and KASAN (Kernel Address Sanitizer) enabled. The severity of this vulnerability is moderate, as it can lead to KASAN reporting invalid access faults, indicating potential memory corruption issues. The attack vector would likely involve a malicious or malformed guest operating system interacting with the host's memory management, but the complexity of exploitation is high given its low-level nature. The potential impact is system instability or crashes due to memory corruption, particularly when KASAN is active. There is no evidence of active exploitation for CVE-2022-50675. No public exploit code or Metasploit modules are available, and there is no significant community discussion or media coverage surrounding this vulnerability. It is not listed on the CISA KEV catalog, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.14CNA affecteddefault affected | |
| Linux | Linux | >= 69e3b846d8a753f9f279f29531ca56b0f7563ad0, < 749e9fc18b1e1a3f93a9512e91bd7f93002d2821, >= 69e3b846d8a753f9f279f29531ca56b0f7563ad0, < 918002bdbe4328c8c0164a22e8ebf2384b80dc23, >= 69e3b846d8a753f9f279f29531ca56b0f7563ad0, < a8e5e5146ad08d794c58252bab00b261045ef16dCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.