Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50249

20
FAUCET Score

CVE-2022-50249 is a refcount leak bug in the Linux kernel's memory management, specifically within the of_get_ddr_timings() function, affecting Linux kernel versions. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and potentially leading to high availability impact. There is currently no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.7, < 4.9.331CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.296CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.262CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.220CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.150CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 29th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-362.8.1.el9_3
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50249Low

kernel: memory: of: Fix refcount leak bug in of_get_ddr_timings()

Sep 15, 2025

References

git.kernel.org / stable/c/05215fb32010d4afb68fbdbb4d237df6e2d4567b
Patch
git.kernel.org / stable/c/1c6cac6fa4d08aea161f83d38117d733b3c3a000
Patch
git.kernel.org / stable/c/2680690f9ce4e6abbb4f559e97271c15b7eeda97
Patch
git.kernel.org / stable/c/62ccab6e3376f8a22167c3b81468ae4f3e7d25f1
Patch
git.kernel.org / stable/c/68c9c4e6495b825be3a8946df1a0148399555fe4
Patch
git.kernel.org / stable/c/85a40bfb8e7a170abcf9dae2c0898a1983e48daa
Patch
git.kernel.org / stable/c/a4d0bd4388e1a39df47e8aaa044ef6a7ee626e48
Patch
git.kernel.org / stable/c/a4f7eb83852a65b6f8dea7dcc42b7c76d4d9b0a3
Patch
git.kernel.org / stable/c/daaec4b3fe2297b022c6b2d6bf48b6e5265a60b9
Patch