Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50503

20
FAUCET Score

CVE-2022-50503 is a null-pointer dereference vulnerability in the Linux kernel's mtd:lpddr2_nvm driver, affecting Linux kernel versions. This medium-severity vulnerability (CVSS 5.5) can lead to a denial of service (A:H) with local access (AV:L) and low privileges (PR:L), requiring low attack complexity (AC:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.16, < 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 30th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-50503

kernel: mtd: lpddr2_nvm: Fix possible null-ptr-deref

Oct 4, 2025

References

git.kernel.org / stable/c/0919982a1744346269320615615c7deb14106661
Patch
git.kernel.org / stable/c/4d10bd7416e8383340b5524b8d616b8ad01ef1e1
Patch
git.kernel.org / stable/c/6bdd45d795adf9e73b38ced5e7f750cd199499ff
Patch
git.kernel.org / stable/c/8eb64dc5a790a529ef49ec94b3337af09dac15d3
Patch
git.kernel.org / stable/c/bb9ccb6121ec4140d366147aa866ceb5a21a8d3d
Patch
git.kernel.org / stable/c/c4cc41e94d8357f5f02b8ef40257bb23931d8438
Patch
git.kernel.org / stable/c/e0d3e46ac6669cdf1b99bc7b7d92f1221b9a1ff2
Patch
git.kernel.org / stable/c/e6aafb57d90ff2c1e18554f3a3c36247a59825ce
Patch
git.kernel.org / stable/c/f82f63b3911f1b2da68a14d9c4babf3b55feca55
Patch