Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50441

20
FAUCET Score

CVE-2022-50441 is a NULL pointer dereference vulnerability in the Linux kernel's net/mlx5 component, specifically affecting the Lag feature. This flaw occurs because a previous commit inadvertently removed a critical call to cancel delayed bond work, leading to the work queue being destroyed while still having queued tasks. This can result in a kernel crash, as evidenced by the provided call trace. The vulnerability has a CVSSv3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and no user interaction. Its primary impact is high availability loss (kernel crash), with no impact on confidentiality or integrity. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or interest.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0.13, < 6.0.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1.1, < 6.1.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1:-:*:*:*:*:*:*
6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1:rc7:*:*:*:*:*:*
6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1:rc8:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 25th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-50441Moderate

kernel: net/mlx5: Lag, fix failure to cancel delayed bond work

Oct 1, 2025

References

git.kernel.org / stable/c/4d1c1379d71777ddeda3e54f8fc26e9ecbfd1009
Patch
git.kernel.org / stable/c/5df57bb04e91add52fb67e226209df9a17f06a89
Patch
git.kernel.org / stable/c/8f1b8b3133504bf9125ee507ddcc3a8fb41a41f0
Patch