CVE-2022-50840 is a Use-After-Free (UAF) vulnerability in the Linux kernel's snic driver, specifically within the snic_tgt_create() function. This flaw occurs if device_add() fails, leading to the freeing of a target (tgt) without its list entry (tgt->list) being removed from snic->disc.tgt_list, which can subsequently cause a UAF during list traversal. While no CVSS score is provided, its low EPSS and FAUCET Risk Score suggest a limited overall impact and difficulty in exploitation. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 4.2CNA affecteddefault affected | |
| Linux | Linux | >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < 1895e908b3ae66a5312fd1b2cdda2da82993dca7, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < 3007f96ca20c848d0b1b052df6d2cb5ae5586e78, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < 3772319e40527e6a5f2ec1d729e01f271d818f5c, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < 4141cd9e8b3379aea52a85d2c35f6eaf26d14e86, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < 6866154c23fba40888ad6d554cccd4bf2edb755e, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < ad27f74e901fc48729733c88818e6b96c813057d, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < c7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27cc, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < e118df492320176af94deec000ae034cc92be754, >= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa, < f9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ffCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.