Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50252

24
FAUCET Score

CVE-2022-50252 is a use-after-free vulnerability in the Linux kernel's igb network driver. This flaw can occur under memory pressure if a kzalloc() call fails, leading to the premature freeing of a q_vector while its pointer remains in the adapter's array. Rated with a CVSS score of 7.8 (HIGH), this vulnerability has a local attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 22nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50252Low

kernel: igb: Do not free q_vector unless new one was allocated

Sep 15, 2025

References

git.kernel.org / stable/c/0200f0fbb11e359cc35af72ab10b2ec224e6f633
Patch
git.kernel.org / stable/c/0668716506ca66f90d395f36ccdaebc3e0e84801
Patch
git.kernel.org / stable/c/314f7092b27749bdde44c14095b5533afa2a3bc8
Patch
git.kernel.org / stable/c/3cb18dea11196fb4a06f78294cec5e61985e1aff
Patch
git.kernel.org / stable/c/56483aecf6b22eb7dff6315b3a174688c6ad494c
Patch
git.kernel.org / stable/c/64ca1969599857143e91aeec4440640656100803
Patch
git.kernel.org / stable/c/68e8adbcaf7a8743e473343b38b9dad66e2ac6f3
Patch
git.kernel.org / stable/c/6e399577bd397a517df4b938601108c63769ce0a
Patch
git.kernel.org / stable/c/f96bd8adc8adde25390965a8c1ee81b73cb62075
Patch