Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50423

24
FAUCET Score

CVE-2022-50423 is a use-after-free vulnerability in the Linux kernel's ACPI subsystem, specifically within the acpi_ut_copy_ipackage_to_ipackage() function. This flaw, introduced by a previous commit, leads to the premature freeing of an acpi_operand_object, resulting in a double-free scenario. With a CVSS score of 7.8 (High), it allows a local attacker to achieve high confidentiality, integrity, and availability impacts with low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.10.55, < 3.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.12.29, < 3.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.14.19, < 3.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.16.3, < 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
5.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 22nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50423Low

kernel: ACPICA: Fix use-after-free in acpi_ut_copy_ipackage_to_ipackage()

Oct 1, 2025

References

git.kernel.org / stable/c/01f2c2052ea50fb9a8ce12e4e83aed0267934ef0
Patch
git.kernel.org / stable/c/02617006b5a46f2ea55ac61f5693c7afd7bf9276
Patch
git.kernel.org / stable/c/02f237423c9c6a18e062de2d474f85d5659e4eb9
Patch
git.kernel.org / stable/c/133462d35dae95edb944af86b986d4c9dec59bd1
Patch
git.kernel.org / stable/c/470188b09e92d83c5a997f25f0e8fb8cd2bc3469
Patch
git.kernel.org / stable/c/6fde666278f91b85d71545a0ebbf41d8d7af8074
Patch
git.kernel.org / stable/c/c9125b643fc51b8e662f2f614096ceb45a0adbc3
Patch
git.kernel.org / stable/c/dfdde4d5138bc023897033a5ac653a84e94805be
Patch
git.kernel.org / stable/c/f51b2235e4f320edc839c3e5cb0d1f8a6e8657c6
Patch