CVE-2022-50879 addresses a NULL pointer dereference vulnerability in the Linux kernel's objtool component. Specifically, the find_insn() function could return NULL, leading to a kernel Oops if not properly handled. While no specific products are listed as affected, this vulnerability impacts the Linux kernel itself. The severity is low, with no CVSS score provided and a FAUCET Risk Score of 7/100. The attack vector and complexity are not detailed, but the potential impact is a system crash (kernel Oops) rather than direct data compromise or privilege escalation. There is no evidence of active exploitation, and no exploit code is publicly available via Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating a low level of attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9.106, < 4.10CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.14.48, < 4.15CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.16.14, < 4.17CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.