CVE-2022-50817 is a null pointer dereference vulnerability in the Linux kernel's High-availability Seamless Redundancy (HSR) networking protocol. It occurs when the create_stripped_skb_hsr() function returns a NULL value, leading to a crash during a subsequent skb_clone() call. This vulnerability affects the Linux kernel, specifically within the HSR module. The severity of this vulnerability is moderate, with a FAUCET Risk Score of 7/100. The attack vector involves triggering the specific condition within the HSR module that causes the null pointer dereference, likely requiring network interaction. The potential impact is a denial-of-service (DoS) due to a kernel crash, which can lead to system instability or unavailability. There is no indication of active exploitation for CVE-2022-50817. No public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB, and there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 3.17CNA affecteddefault affected | |
| Linux | Linux | >= f266a683a4804dc499efc6c2206ef68efed029d0, < 35ece858660eae13ee0242496a1956c39d29418e, >= f266a683a4804dc499efc6c2206ef68efed029d0, < c46f2e0fcd1ecfc6046e5cf785ff89f0572f94e4, >= f266a683a4804dc499efc6c2206ef68efed029d0, < d8b57135fd9ffe9a5b445350a686442a531c5339, >= f266a683a4804dc499efc6c2206ef68efed029d0, < ff7ba766758313129794f150bbc4d351b5e17a53CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.