Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50309

18
FAUCET Score

CVE-2022-50309 is a refcount leak vulnerability in the Xilinx VIPP driver within the Linux kernel, affecting versions of Linux and its kernel. The vulnerability, rated Medium with a CVSS score of 5.5, could lead to a denial of service (A:H) if a local attacker (AV:L/PR:L) successfully exploits it with low attack complexity (AC:L). There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.1, < 4.9.331CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.296CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.262CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.220CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.150CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 29th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-50309

kernel: media: xilinx: vipp: Fix refcount leak in xvip_graph_dma_init

Sep 15, 2025

References

git.kernel.org / stable/c/1c78f19c3a0ea312a8178a6bfd8934eb93e9b10a
Patch
git.kernel.org / stable/c/22b93530bbe6af9dce8e520bb6e978d1bda39d2b
Patch
git.kernel.org / stable/c/2630cc88327a5557aa0d9cc63be95e3c6e0a55b3
Patch
git.kernel.org / stable/c/2ea7caa9684687cf3adc1467cf4af3653a776192
Patch
git.kernel.org / stable/c/3336210948b22c2db43e9df2ea403d251b4d24ab
Patch
git.kernel.org / stable/c/3c38467c3255c428cdbd3cefaccca4662f302dc9
Patch
git.kernel.org / stable/c/59b315353252abe7b8fdb8651ca31b8484ce287a
Patch
git.kernel.org / stable/c/6e7b3b1e4e9f739800cd8010b75a9bee8d808cee
Patch
git.kernel.org / stable/c/7b0efe7534071e0153708886355d80db69525d50
Patch