Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50028

15
FAUCET Score

CVE-2022-50028 is a medium-severity vulnerability in the Linux kernel's gadgetfs component. It arises when an interrupt occurs after usb_ep_queue() but before the IRQ finishes, potentially leading to stack corruption. With a CVSS score of 5.5, this local vulnerability requires low privileges and has a high impact on availability, though confidentiality and integrity are not affected. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat landscape.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.326CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.291CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.256CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.211CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.138CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 34th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.11.1.el9_2
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50028Moderate

kernel: gadgetfs: ep_io - wait until IRQ finishes

Jun 18, 2025

References

git.kernel.org / stable/c/04cb742d4d8f30dc2e83b46ac317eec09191c68e
Patch
git.kernel.org / stable/c/118d967ce00a3d128bf731b35e4e2cb0facf5f00
Patch
git.kernel.org / stable/c/2b06d5d97c0e067108a122986767731d40742138
Patch
git.kernel.org / stable/c/67a4874461422e633236a0286a01b483cd647113
Patch
git.kernel.org / stable/c/77040efe59a141286d090c8a0d37c65a355a1832
Patch
git.kernel.org / stable/c/94aadba8d000d5de56af4ce8da3f334f21bf7a79
Patch
git.kernel.org / stable/c/9ac14f973cb91f0c01776517e6d50981f32b8038
Patch
git.kernel.org / stable/c/ca06b4cde54f8ec8be3aa53fd339bd56e62c12b3
Patch