Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50280

20
FAUCET Score

CVE-2022-50280 is a NULL dereference vulnerability in the Linux kernel's mount propagation mechanism, specifically within the propagate_mnt() function. This flaw occurs because the function fails to correctly terminate at peers of the source mount, leading to a NULL pointer dereference. The vulnerability affects the Linux kernel and can be triggered by unprivileged users due to its availability through unprivileged user namespaces. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity and no user interaction required. A successful exploit could lead to high availability impact, likely causing a system crash or denial of service. There is no known evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.14.3, < 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 30th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50280Moderate

kernel: pnode: terminate at peers of source

Sep 15, 2025

References

git.kernel.org / stable/c/11933cf1d91d57da9e5c53822a540bbdc2656c16
Patch
git.kernel.org / stable/c/2dae4211b579ce98985876a73a78466e285238ff
Patch
git.kernel.org / stable/c/784a4f995ee24460aa72e00b085612fad57ebce5
Patch
git.kernel.org / stable/c/7f57df69de7f05302fad584eb8e3f34de39e0311
Patch
git.kernel.org / stable/c/b591b2919d018ef91b4a9571edca94105bcad3df
Patch
git.kernel.org / stable/c/c24cc476acd8bccb5af54849aac5e779d8223bf5
Patch
git.kernel.org / stable/c/cad0d17fb2b0540180ab59e2cd48ad348cc1ee4c
Patch
git.kernel.org / stable/c/cc997490be65da0af8c75a6244fc80bb66c53ce0
Patch
git.kernel.org / stable/c/e7c9f10c44a8919cd8bbd51b228c84d0caf7d518
Patch