CVE-2022-50819 addresses a null-pointer dereference vulnerability in the Linux kernel's udmabuf driver. This flaw occurs when userspace attempts to map a dmabuf, and the creation of the scatter-gather (SG) table fails, but the ubuf->sg pointer is not properly nulled. Consequently, upon closing the dmabuf file descriptor, the system attempts to free an invalid SG table, leading to a kernel crash. The severity of this vulnerability is moderate. It requires local access to trigger the condition, and its complexity is low as it can be caused by resource exhaustion (e.g., OOM). The potential impact is a denial of service due to a kernel panic, which can lead to system instability and unavailability. There is no evidence of active exploitation for CVE-2022-50819. No public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB, and there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.6CNA affecteddefault affected | |
| Linux | Linux | >= 284562e1f34874e267d4f499362c3816f8f6bc3f, < 9861e43f097a50678041f973347b3a88f2da09cf, >= 284562e1f34874e267d4f499362c3816f8f6bc3f, < bbe2f6f90310b3a0b5de4e0dc022b36faabfd718, >= 284562e1f34874e267d4f499362c3816f8f6bc3f, < d9c04a1b7a15b5e74b2977461d9511e497f05d8f, >= 284562e1f34874e267d4f499362c3816f8f6bc3f, < dfbed8c92eb853929f4fa676ba493391dab47be4, >= 284562e1f34874e267d4f499362c3816f8f6bc3f, < fc285549f454c0f50f87ec945fc0bf44719c0fa4CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.