CVE-2022-50697 is a use-after-free vulnerability in the Linux kernel's Multiple Registration Protocol (MRP) implementation. It occurs due to a race condition where a timer can be restarted after its cancellation, leading to memory corruption. This vulnerability affects the Linux kernel, specifically within the net/802/mrp.c module. The vulnerability has a low FAUCET Risk Score of 7/100, indicating a relatively low severity. The attack vector involves a timing issue within the kernel, making exploitation complex. The potential impact is a system crash (denial of service) as demonstrated by the KASAN report, but could potentially lead to more severe outcomes depending on the specific memory corruption. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 3.9CNA affecteddefault affected | |
| Linux | Linux | >= febf018d22347b5df94066bca05d0c11a84e839d, < 1a185fe83c2a60c1e3596fb9d82dbeb148dc09c6, >= febf018d22347b5df94066bca05d0c11a84e839d, < 563e45fd5046045cc194af3ba17f5423e1c98170, >= febf018d22347b5df94066bca05d0c11a84e839d, < 5d5a481a7fd0234f617535dc464ea010804a1129, >= febf018d22347b5df94066bca05d0c11a84e839d, < 755eb0879224ffc2a43de724554aeaf0e51e5a64, >= febf018d22347b5df94066bca05d0c11a84e839d, < 78d48bc41f7726113c9f114268d3ab11212814da, >= febf018d22347b5df94066bca05d0c11a84e839d, < 98f53e591940e4c3818be358c5dc684d5b30cb56, >= febf018d22347b5df94066bca05d0c11a84e839d, < aacffc1a8dbf67c5463cb4f67b37143c01ca6fa9, >= febf018d22347b5df94066bca05d0c11a84e839d, < aadb1507a77b060c529edfeaf67f803e31461f24, >= febf018d22347b5df94066bca05d0c11a84e839d, < ab0377803dafc58f1e22296708c1c28e309414d6CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.