Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50737

11
FAUCET Score

CVE-2022-50737 is a use-after-free vulnerability in the Linux kernel's NTFS3 filesystem driver. Specifically, it occurs during the initialization of NTFS security when validating index roots ($SDH and $SII). This flaw could lead to a system crash, as indicated by the KASAN report showing a "BUG: KASAN: use-after-free" during a mount operation. The severity of this vulnerability is moderate. The attack vector likely involves mounting a specially crafted NTFS filesystem, which could be done locally or potentially remotely if an attacker can trick a user into mounting such a filesystem. The complexity appears to be low to medium, as it exploits a logic error in sanity checks. The potential impact is a denial-of-service (system crash) due to memory corruption. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage around this CVE are minimal, suggesting low public awareness and attention.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
5.15CNA affecteddefault affected
LinuxLinux
>= 82cae269cfa953032fbb8980a7d554d60fb00b17, < 24ee53c6bce15500db22f2a7aee9dd830e806c90, >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < bfcdbae0523bd95eb75a739ffb6221a37109881e, >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < d6379ce242960a8e9ecd6ff76f476d9336c21f16, >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < d7ce7bb6881aae186e50f57eea935cff8d504751CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Vendor Advisories (1)

redhatCVE-2022-50737Moderate

kernel: fs/ntfs3: Validate index root when initialize NTFS security

Dec 24, 2025

References

git.kernel.org / stable/c/24ee53c6bce15500db22f2a7aee9dd830e806c90
git.kernel.org / stable/c/bfcdbae0523bd95eb75a739ffb6221a37109881e
git.kernel.org / stable/c/d6379ce242960a8e9ecd6ff76f476d9336c21f16
git.kernel.org / stable/c/d7ce7bb6881aae186e50f57eea935cff8d504751