CVE-2022-50677

HIGHCVSS 7/10EPSS 0.22%

Last modified

CVE-2022-50677 is a high-severity vulnerability rated 7/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.

Metrics

CVSS 3.1
7/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.22%

13.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f9d405a4bd6090ffbf3bba5e2da6b44c0e013cb3, < 35ad87bfe330f7ef6a19f772223c63296d643172; >= b642ced2cad496c32ae1f62b85fc395391190820, < d23006f2a56e11a3103de0ca8b843bf7fd7d76fc; >= cbb79863fc3175ed5ac506465948b02a893a8235, < f29d127b372e1b7662397d92341d9f7de198ff99; >= cbb79863fc3175ed5ac506465948b02a893a8235, < bfce073089cb81482521c65061835aaa6d1a6cc0; >= cbb79863fc3175ed5ac506465948b02a893a8235, < f7fde441198a9ecb130c3ccec91ee2131d6998ee; >= cbb79863fc3175ed5ac506465948b02a893a8235, < 1fc9b20a7688000fcf4d7fbaa58e415a3cdda961; >= cbb79863fc3175ed5ac506465948b02a893a8235, < a92ce570c81dc0feaeb12a429b4bc65686d17967; >= 4.19.92, < 4.19.270; >= 5.4.7, < 5.4.229
LinuxLinux5.5

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50677?
In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.
How severe is CVE-2022-50677?
CVE-2022-50677 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50677?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50677?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST