CVE-2022-50677
Last modified
CVE-2022-50677 is a high-severity vulnerability rated 7/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= f9d405a4bd6090ffbf3bba5e2da6b44c0e013cb3, < 35ad87bfe330f7ef6a19f772223c63296d643172; >= b642ced2cad496c32ae1f62b85fc395391190820, < d23006f2a56e11a3103de0ca8b843bf7fd7d76fc; >= cbb79863fc3175ed5ac506465948b02a893a8235, < f29d127b372e1b7662397d92341d9f7de198ff99; >= cbb79863fc3175ed5ac506465948b02a893a8235, < bfce073089cb81482521c65061835aaa6d1a6cc0; >= cbb79863fc3175ed5ac506465948b02a893a8235, < f7fde441198a9ecb130c3ccec91ee2131d6998ee; >= cbb79863fc3175ed5ac506465948b02a893a8235, < 1fc9b20a7688000fcf4d7fbaa58e415a3cdda961; >= cbb79863fc3175ed5ac506465948b02a893a8235, < a92ce570c81dc0feaeb12a429b4bc65686d17967; >= 4.19.92, < 4.19.270; >= 5.4.7, < 5.4.229 |
| Linux | Linux | 5.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50677?
How severe is CVE-2022-50677?
How do I fix CVE-2022-50677?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50671In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2022-50672In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50673In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50674In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50675In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50676In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2022-50678In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50679In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50680A stored cross-site scripting vulnerability in Kentico Xperi…4.8
- CVE-2022-50681A reflected cross-site scripting vulnerability in Kentico Xp…6.1
- CVE-2022-50682A CRLF injection vulnerability in Kentico Xperience allows a…6.9
- CVE-2022-50683A stored cross-site scripting vulnerability in Kentico Xperi…5.4
Are you affected by CVE-2022-50677?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
