CVE-2022-50737 is a use-after-free vulnerability in the Linux kernel's NTFS3 filesystem driver. Specifically, it occurs during the initialization of NTFS security when validating index roots ($SDH and $SII). This flaw could lead to a system crash, as indicated by the KASAN report showing a "BUG: KASAN: use-after-free" during a mount operation. The severity of this vulnerability is moderate. The attack vector likely involves mounting a specially crafted NTFS filesystem, which could be done locally or potentially remotely if an attacker can trick a user into mounting such a filesystem. The complexity appears to be low to medium, as it exploits a logic error in sanity checks. The potential impact is a denial-of-service (system crash) due to memory corruption. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage around this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.15CNA affecteddefault affected | |
| Linux | Linux | >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < 24ee53c6bce15500db22f2a7aee9dd830e806c90, >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < bfcdbae0523bd95eb75a739ffb6221a37109881e, >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < d6379ce242960a8e9ecd6ff76f476d9336c21f16, >= 82cae269cfa953032fbb8980a7d554d60fb00b17, < d7ce7bb6881aae186e50f57eea935cff8d504751CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.