Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50481

20
FAUCET Score

CVE-2022-50481 is a null-pointer dereference vulnerability in the Linux kernel's CXL subsystem, specifically within the cxl_guest_init_afu and cxl_guest_init_adapter functions. This medium-severity flaw (CVSS 5.5) could lead to a denial of service (availability impact) if device_register() fails, due to an incorrect error handling path. The vulnerability has a low attack complexity and requires local privileges to exploit. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.6, < 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 29th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50481Low

kernel: cxl: fix possible null-ptr-deref in cxl_guest_init_afu|adapter()

Oct 4, 2025

References

git.kernel.org / stable/c/170e8c2d2b61e15e7f7cfeded81bc1e959a15ed8
Patch
git.kernel.org / stable/c/1ae581696b7a799afa39a664c4b721569643f58a
Patch
git.kernel.org / stable/c/60b2ed21a65f3f5318666ccd765c3507991370cf
Patch
git.kernel.org / stable/c/61c80d1c3833e196256fb060382db94f24d3d9a7
Patch
git.kernel.org / stable/c/96fba6fb95bdede80583c262ac185da09661f264
Patch
git.kernel.org / stable/c/ab44c182353be101c3be9465e1d15d42130c53c4
Patch
git.kernel.org / stable/c/b32559ee4e6667c5c3daf4ec5454c277d1f255d2
Patch
git.kernel.org / stable/c/d775a1da5a52b4f4bb02f2707ba420d1bec48dbb
Patch
git.kernel.org / stable/c/e5021bbf11b024cc65ea1e84c377df484183be4b
Patch