CVE-2022-50335
A flaw in the Linux kernel's 9p file system implementation allows for the use of uninitialized memory. This occurs when a new request is added to the system before its reference count is properly set.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel that utilize the 9p file system.
Real-world impact
An attacker could potentially cause a system crash or execute arbitrary code by exploiting the corrupted memory and incorrect reference counting.
Why this severity
The critical score reflects that this vulnerability can be exploited remotely over a network without authentication or user interaction, potentially leading to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Update the Linux kernel to the version containing the fix for CVE-2022-50335.
NVD-referenced vendor advisory
Timeline
- Sep 15, 2025 · Sep 15, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.