
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-50798 is a rejected CVE that was determined to be a duplicate of CVE-2017-11359. It was originally described as a divide-by-zero vulnerability in SoX (Sound eXchange) 14.4.2 affecting WAV file processing, capable of causing program crashes via a specially crafted audio file. The CVE was published on December 30, 2025, and subsequently rejected by the CVE Program. The associated CVSS v3.1 score was 7.5 (High) and CVSS v4.0 score was 6.7 (Medium) (Feedly, EUVD).
The underlying flaw (tracked under the canonical CVE-2017-11359) is classified as CWE-369 (Divide By Zero). When SoX 14.4.2 processes a maliciously crafted WAV file, arithmetic errors during sound file parsing trigger a floating-point exception, causing the application to crash. Exploitation requires an attacker to supply a specially crafted WAV file to a vulnerable SoX instance. A proof-of-concept exploit is publicly available on Exploit-DB (Exploit-DB, ZeroScience).
Successful exploitation results in a denial-of-service condition — the SoX process crashes due to a floating-point exception, disrupting any audio processing pipeline or service relying on SoX. There is no impact on confidentiality or integrity; only availability is affected. The impact is limited to the local SoX process and does not facilitate lateral movement or data exfiltration (Feedly, VulnCheck).
A public proof-of-concept exploit is available on Exploit-DB (exploit ID 51034). The EPSS score is approximately 0.03%, indicating low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and this CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (providing a crafted WAV file) but no authentication or special privileges (Exploit-DB, Feedly).
sox malicious.wav output.wav), which triggers a floating-point exception during WAV header or data parsing./var/log/syslog) showing repeated SoX crashes or SIGFPE signals; application logs indicating failed audio file processing.Since CVE-2022-50798 is a rejected duplicate of CVE-2017-11359, remediation should reference the canonical CVE. Users should upgrade SoX to a version that addresses CVE-2017-11359, or apply patches provided by their Linux distribution (e.g., Amazon Linux 2 advisory ALAS2-2026-3129 addresses this issue). As a workaround, restrict processing of untrusted WAV files through SoX and validate audio file integrity before processing. No dedicated patch exists specifically for CVE-2022-50798 given its rejected status (Amazon Linux Advisory, VulnCheck).
The vulnerability received limited attention, primarily appearing in automated vulnerability feeds and scanner databases (Nessus plugin 281521, VulDB, Vulners). A CISA weekly vulnerability bulletin for the week of December 29, 2025 referenced it. Social media mentions were minimal and automated in nature, with posts on Bluesky and Mastodon from vulnerability tracking bots (CISA Bulletin, Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."