Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50359

20
FAUCET Score

CVE-2022-50359 is a null-pointer dereference vulnerability in the Linux kernel's cx88 media driver, specifically within the buffer_prepare() function. This flaw occurs when cx88_risc_buffer() fails to prepare a buffer, leading to a subsequent dereference of a null pointer in buffer_queue(). With a CVSS score of 5.5 (Medium), it can be exploited locally with low attack complexity, potentially leading to a denial of service (system crash). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.331CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.296CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.262CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.220CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.150CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 47th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50359Moderate

kernel: media: cx88: Fix a null-ptr-deref bug in buffer_prepare()

Sep 17, 2025

References

git.kernel.org / stable/c/10c99d1c46ea9cd940029e17bab11d021f315c21
Patch
git.kernel.org / stable/c/2b064d91440b33fba5b452f2d1b31f13ae911d71
Patch
git.kernel.org / stable/c/4befc7ffa18ef9a4b70d854465313a345a06862f
Patch
git.kernel.org / stable/c/644d5a87ab1863eb606526ea743021752a17e9cb
Patch
git.kernel.org / stable/c/6f21976095c1e92454ab030976f95f40d652351b
Patch
git.kernel.org / stable/c/704838040f3bdb4aa07ff4f26505a666a3defcfe
Patch
git.kernel.org / stable/c/9181af2dbf06e7f432e5dbe88d10b22343e851b9
Patch
git.kernel.org / stable/c/c2257c8a501537afab276c306cb717b7260276e1
Patch
git.kernel.org / stable/c/c76d04d2079a4b7369ce9a0e859c0f3f2250bcc1
Patch