Review reviewHigh

CVE-2022-50677

Linux

In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.

CVSS
7
EPSS
0.15%
5.06% percentile
CISA KEV
Not listed
Published
2025.12.10
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() The intf_free() function frees the "intf" pointer so we cannot dereference it again on the next line.

Affected product and versions

Product
Linux
Affected versions
>= f9d405a4bd6090ffbf3bba5e2da6b44c0e013cb3 < 35ad87bfe330f7ef6a19f772223c63296d643172, >= b642ced2cad496c32ae1f62b85fc395391190820 < d23006f2a56e11a3103de0ca8b843bf7fd7d76fc, >= cbb79863fc3175ed5ac506465948b02a893a8235 < f29d127b372e1b7662397d92341d9f7de198ff99, >= cbb79863fc3175ed5ac506465948b02a893a8235 < bfce073089cb81482521c65061835aaa6d1a6cc0, >= cbb79863fc3175ed5ac506465948b02a893a8235 < f7fde441198a9ecb130c3ccec91ee2131d6998ee, >= cbb79863fc3175ed5ac506465948b02a893a8235 < 1fc9b20a7688000fcf4d7fbaa58e415a3cdda961, >= cbb79863fc3175ed5ac506465948b02a893a8235 < a92ce570c81dc0feaeb12a429b4bc65686d17967, >= 4.19.92 < 4.19.270, >= 5.4.7 < 5.4.229, >= 5.5
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2022-50677 — Linux | SECUFOCUS NOW