Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50563

11
FAUCET Score

CVE-2022-50563 is a use-after-free (UAF) vulnerability in the Linux kernel's device mapper (dm) thin provisioning module. Specifically, it occurs when dm_resume() and dm_destroy() operations are executed concurrently, leading to a race condition where a timer is added by dm_resume() but not cancelled by dm_destroy() due to the suspended status. This results in the timer attempting to access freed memory when it eventually fires. The vulnerability has no assigned CVSS score, but its FAUCET Risk Score is 5/100, indicating a low to moderate severity. The attack vector involves a race condition during specific device mapper operations, and the potential impact is a system crash (kernel panic) due to the UAF, leading to denial of service. There is no evidence of active exploitation, exploit code availability (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in CISA's Known Exploited Vulnerabilities Catalog.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
3.2CNA affecteddefault affected
LinuxLinux
>= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 34cd15d83b7206188d440b29b68084fcafde9395, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 34fe9c2251f19786a6689149a6212c6c0de1d63b, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 550a4fac7ecfee5bac6a0dd772456ca62fb72f46, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 7ae6aa649394e1e7f6dafb55ce0d578c0572a280, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 7ee059d06a5d3c15465959e0472993e80fbe4e81, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 88430ebcbc0ec637b710b947738839848c20feff, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < 94e231c9d6f2648d2f1f68e7f476e050ee0a6159, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < d9971fa4d8bde63d49c743c1b32d12fbbd3a30bd, >= 991d9fa02da0dd1f843dc011376965e0c8c6c9b5, < e8b8e0d2bbf7d1172c4f435621418e29ee408d46CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-477.10.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.11.1.el9_2
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-50563Moderate

kernel: dm thin: Fix UAF in run_timer_softirq()

Oct 22, 2025

References

git.kernel.org / stable/c/34cd15d83b7206188d440b29b68084fcafde9395
git.kernel.org / stable/c/34fe9c2251f19786a6689149a6212c6c0de1d63b
git.kernel.org / stable/c/550a4fac7ecfee5bac6a0dd772456ca62fb72f46
git.kernel.org / stable/c/7ae6aa649394e1e7f6dafb55ce0d578c0572a280
git.kernel.org / stable/c/7ee059d06a5d3c15465959e0472993e80fbe4e81
git.kernel.org / stable/c/88430ebcbc0ec637b710b947738839848c20feff
git.kernel.org / stable/c/94e231c9d6f2648d2f1f68e7f476e050ee0a6159
git.kernel.org / stable/c/d9971fa4d8bde63d49c743c1b32d12fbbd3a30bd
git.kernel.org / stable/c/e8b8e0d2bbf7d1172c4f435621418e29ee408d46