Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50337

20
FAUCET Score

CVE-2022-50337 is a refcount leak vulnerability in the Linux kernel's ocxl driver, specifically within the get_function_0() and get_dvsec_vendor0() functions, affecting Linux kernel versions. Rated Medium with a CVSS score of 5.5, this local vulnerability could lead to a denial of service (A:H) due to resource exhaustion, requiring low privileges (PR:L) and no user interaction (UI:N). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.9, < 5.10.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.86CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.0.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1, < 6.1.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 26th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50337Low

kernel: ocxl: fix pci device refcount leak when calling get_function_0()

Sep 15, 2025

References

git.kernel.org / stable/c/27158c72678b39ee01cc01de1aba6b51c71abe2f
Patch
git.kernel.org / stable/c/37a13b274e4513c757e50c002ddcbf4bc89adbb2
Patch
git.kernel.org / stable/c/40ff4c2335a98f0ee96b099bfd70b8e6644f321f
Patch
git.kernel.org / stable/c/9a1b3148975b71fdc194e62612478346bbe618cd
Patch
git.kernel.org / stable/c/a40e1b0a922a53fa925ea8b296e3de30a31ed028
Patch