CVE-2022-50679 describes a DMA mapping leak vulnerability in the Linux kernel's i40e network driver. This flaw occurs during the reallocation of RX buffers, where new DMA mappings are created but older, already mapped buffers are not properly freed, leading to a memory leak. The vulnerability can be triggered by repeatedly adjusting the RX/TX ring parameters using ethtool, potentially causing a kernel crash due to memory exhaustion. The severity of this vulnerability is moderate. It requires local access to execute ethtool commands, making the attack vector local. The complexity is low, as the reproduction steps are straightforward. The potential impact is a denial-of-service (DoS) due to a kernel crash, which can disrupt system availability. There is no evidence of active exploitation for CVE-2022-50679. No exploit code is publicly available on platforms like Metasploit or ExploitDB, and there is minimal community discussion or media coverage, indicating a low level of attention from threat actors and researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.8CNA affecteddefault affected | |
| Linux | Linux | >= be1222b585fdc410b8c1dbcc57dd03a00f04eff5, < 5f499596dfa3db9b3172645b6de9e1096a669c95, >= be1222b585fdc410b8c1dbcc57dd03a00f04eff5, < 94a171c982b8a8137a00721c1e62bc2713435bca, >= be1222b585fdc410b8c1dbcc57dd03a00f04eff5, < aae425efdfd1b1d8452260a3cb49344ebf20b1f5, >= be1222b585fdc410b8c1dbcc57dd03a00f04eff5, < ed5baf3d0a33caaca4cd4073ebb0854cc77a616dCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.