CVE-2022-50843

UnknownEPSS 0.21%

Last modified

CVE-2022-50843 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: dm clone: Fix UAF in clone_dtr() Dm_clone also has the same UAF problem when dm_resume() and dm_destroy() are concurrent. Therefore, cancelling timer again in clone_dtr().. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: dm clone: Fix UAF in clone_dtr() Dm_clone also has the same UAF problem when dm_resume() and dm_destroy() are concurrent. Therefore, cancelling timer again in clone_dtr().

Metrics

EPSS Probability
0.21%

10.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 7431b7835f554f8608b415a02cf3c3f086309e02, < 520b56cfd9faee7683f081c3a38f11a81b13a68e; >= 7431b7835f554f8608b415a02cf3c3f086309e02, < 342cfd8426dff4228e6c714bcb9fc8295a2748dd; >= 7431b7835f554f8608b415a02cf3c3f086309e02, < 856edd0e92f3fe89606b704c86a93daedddfe6ec; >= 7431b7835f554f8608b415a02cf3c3f086309e02, < b1ddb666073bb5f36390aaabaa1a4d48d78c52ed; >= 7431b7835f554f8608b415a02cf3c3f086309e02, < 9e113cd4f61f3b0000843b2d0a90ce8b40a1fcff; >= 7431b7835f554f8608b415a02cf3c3f086309e02, < e4b5957c6f749a501c464f92792f1c8e26b61a94
LinuxLinux5.4

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50843?
In the Linux kernel, the following vulnerability has been resolved: dm clone: Fix UAF in clone_dtr() Dm_clone also has the same UAF problem when dm_resume() and dm_destroy() are concurrent. Therefore, cancelling timer again in clone_dtr().
How severe is CVE-2022-50843?
Severity scoring for CVE-2022-50843 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50843?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50843?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST