CVE-2022-50865 is a signed-integer-overflow vulnerability in the Linux kernel's tcp_add_backlog() function. This flaw arises when calculating a buffer limit, where the sum of sk_rcvbuf, sk_sndbuf, and a fixed value can exceed the maximum integer value, leading to an overflow. The fix addresses this by reducing the limit budget. While a CVSS score is not provided, the FAUCET Risk Score is 7/100, indicating a low severity. The vulnerability's complexity and potential impact are not detailed, but it likely affects the stability or performance of TCP connections rather than direct remote code execution. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. This suggests a low current threat landscape for this specific vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 4.9CNA affecteddefault affected | |
| Linux | Linux | >= c9c3321257e1b95be9b375f811fb250162af8d39, < 28addf029417d53b1df062b4c87feb7bc033cb5f, >= c9c3321257e1b95be9b375f811fb250162af8d39, < 4f23cb2be530785db284a685d1b1c30224d8a538, >= c9c3321257e1b95be9b375f811fb250162af8d39, < 9d04b4d0feee12bce6bfe37f30d8e953d3c30368, >= c9c3321257e1b95be9b375f811fb250162af8d39, < a85d39f14aa8a71e29cfb5eb5de02878a8779898, >= c9c3321257e1b95be9b375f811fb250162af8d39, < ec791d8149ff60c40ad2074af3b92a39c916a03fCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.