CVE-2022-50854 is a memory leak vulnerability in the Linux kernel's NFC virtual_ncidev driver. Specifically, the skb (socket buffer) is not properly freed in the virtual_nci_send() function, leading to memory exhaustion over time. This issue affects the Linux kernel and can be reproduced by running NCI selftests. The severity of this vulnerability is relatively low. It is a memory leak, which typically leads to denial-of-service through resource exhaustion rather than direct arbitrary code execution. There is no CVSS score provided, but its FAUCET Risk Score is 7/100, indicating minimal risk. There is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are also non-existent, suggesting a lack of widespread attention or concern regarding this particular vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.12CNA affecteddefault affected | |
| Linux | Linux | >= e624e6c3e777fb3dfed036b9da4d433aee3608a5, < 2c46a9a5f0b1c7341aa67667801079f3ff571678, >= e624e6c3e777fb3dfed036b9da4d433aee3608a5, < 88e879c9f59511174ef0ab1a3c9c83e2dbf8a213, >= e624e6c3e777fb3dfed036b9da4d433aee3608a5, < e840d8f4a1b323973052a1af5ad4edafcde8ae3dCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.