Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-47085

20
FAUCET Score

CVE-2022-47085 is a denial-of-service vulnerability affecting ostree versions prior to 2022.7, stemming from an issue within the print_panic function in repo_checkout_filter.rs. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely without user interaction, potentially leading to a denial of service or other unspecified impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2022.7CPE matchmatch criteria
cpe:2.3:a:ostree_project:ostree:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.87%
Probability of exploitation in next 30 days
EPSS Percentile
55.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0087 is in the 30th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 19905-17084Fixed in: 2024.5-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2022.1-7
microsoftpatch availablevia msrc
Product: 18815-17084Fixed in: 2022.1-7
microsoftpatch availablevia msrc
Product: azl3 rpm-ostree 2022.1-7 on Azure Linux 3.0Fixed in: 2022.1-7
microsoftpatch availablevia msrc
Product: azl3 ostree 2022.1-4 on Azure Linux 3.0Fixed in: 2024.5-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2022.1-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2022.1-5
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2024.5-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2022.1-7
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2024.5-1
rustpatch availablevia ghsa
Product: ostreeFixed in: 0.17.1
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: ostree

Vendor Advisories (4)

microsoft2024-Jun/CVE-2022-47085

CVE-2022-47085

Jun 11, 2024
redhatCVE-2022-47085Moderate

ostree: DoS via print_panic function

Nov 26, 2023
rustGHSA-x96g-95fq-4xv4medium

libostree vulnerable to denial of service attack

Jul 18, 2023
microsoft2023-Jul/CVE-2022-47085Important

An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.

Jul 11, 2023

References

doc.rust-lang.org / std/macro.eprintln.html
Exploit
github.com / ostreedev/ostree/issues/2775
Issue TrackingPatch