CVE-2022-50798
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-50798 is a rejected CVE that was determined to be a duplicate of CVE-2017-11359. It was originally described as a divide-by-zero vulnerability in SoX (Sound eXchange) 14.4.2 affecting WAV file processing, capable of causing program crashes via a specially crafted audio file. The CVE was published on December 30, 2025, and subsequently rejected by the CVE Program. The associated CVSS v3.1 score was 7.5 (High) and CVSS v4.0 score was 6.7 (Medium) (Feedly, EUVD).

Technical details

The underlying flaw (tracked under the canonical CVE-2017-11359) is classified as CWE-369 (Divide By Zero). When SoX 14.4.2 processes a maliciously crafted WAV file, arithmetic errors during sound file parsing trigger a floating-point exception, causing the application to crash. Exploitation requires an attacker to supply a specially crafted WAV file to a vulnerable SoX instance. A proof-of-concept exploit is publicly available on Exploit-DB (Exploit-DB, ZeroScience).

Impact

Successful exploitation results in a denial-of-service condition — the SoX process crashes due to a floating-point exception, disrupting any audio processing pipeline or service relying on SoX. There is no impact on confidentiality or integrity; only availability is affected. The impact is limited to the local SoX process and does not facilitate lateral movement or data exfiltration (Feedly, VulnCheck).

Exploitability

A public proof-of-concept exploit is available on Exploit-DB (exploit ID 51034). The EPSS score is approximately 0.03%, indicating low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and this CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (providing a crafted WAV file) but no authentication or special privileges (Exploit-DB, Feedly).

Exploitation steps

  1. Craft malicious WAV file: Create or obtain a specially crafted WAV file designed to trigger a divide-by-zero arithmetic error during SoX's WAV parsing routines (a sample PoC is available at Exploit-DB ID 51034).
  2. Deliver the file: Provide the malicious WAV file to a system running SoX 14.4.2, either by direct file transfer, via a web upload form, or through any pipeline that passes audio files to SoX for processing.
  3. Trigger processing: Cause SoX to process the crafted file (e.g., sox malicious.wav output.wav), which triggers a floating-point exception during WAV header or data parsing.
  4. Achieve denial of service: The SoX process crashes with a floating-point exception (SIGFPE), disrupting any dependent audio processing service (Exploit-DB, ZeroScience).

Indicators of compromise

  • Process: SoX process terminating unexpectedly with a floating-point exception (SIGFPE signal) or segmentation fault when processing WAV files.
  • Logs: System logs (e.g., /var/log/syslog) showing repeated SoX crashes or SIGFPE signals; application logs indicating failed audio file processing.
  • File System: Presence of unexpected or anomalous WAV files in directories monitored by SoX or audio processing pipelines, particularly files with malformed headers or unusual metadata.

Mitigation and workarounds

Since CVE-2022-50798 is a rejected duplicate of CVE-2017-11359, remediation should reference the canonical CVE. Users should upgrade SoX to a version that addresses CVE-2017-11359, or apply patches provided by their Linux distribution (e.g., Amazon Linux 2 advisory ALAS2-2026-3129 addresses this issue). As a workaround, restrict processing of untrusted WAV files through SoX and validate audio file integrity before processing. No dedicated patch exists specifically for CVE-2022-50798 given its rejected status (Amazon Linux Advisory, VulnCheck).

Community reactions

The vulnerability received limited attention, primarily appearing in automated vulnerability feeds and scanner databases (Nessus plugin 281521, VulDB, Vulners). A CISA weekly vulnerability bulletin for the week of December 29, 2025 referenced it. Social media mentions were minimal and automated in nature, with posts on Bluesky and Mastodon from vulnerability tracking bots (CISA Bulletin, Tenable).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-doc
NoYesSep 10, 2026
CVE-2026-88924HIGH7
  • Linux Debian logoLinux Debian
  • gvfs-afp
NoNoSep 10, 2026
CVE-2026-87933MEDIUM5.5
  • Linux Debian logoLinux Debian
  • cjson
NoNoSep 10, 2026
CVE-2026-61915MEDIUM4.2
  • Linux Debian logoLinux Debian
  • cyrus-imapd-doc-extra
NoNoSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management