Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-50828

11
FAUCET Score

CVE-2022-50828 is a stack-out-of-bounds vulnerability in the Linux kernel's ZynqMP clock driver, specifically affecting the strncpy function. When a clock name exceeds 15 bytes, the Linux-ATF interface fails to null-terminate the string, leading to memory corruption. This issue primarily impacts systems utilizing Xilinx Zynq UltraScale+ MPSoC and Versal ACAP devices. The vulnerability has a low attack complexity as it can be triggered by providing an overly long clock name, potentially leading to system instability, denial of service, or information disclosure. While no CVSS score is provided, the KASAN report indicates a critical memory safety issue. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE. It is not listed on the CISA KEV catalog, suggesting it is not widely exploited in the wild.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
5.2CNA affecteddefault affected
LinuxLinux
>= 5852b1365df4414523210e444ac7df1dec09acb4, < 0a07b13af04d0db7325018aaa83b5ffe864790c9, >= 5852b1365df4414523210e444ac7df1dec09acb4, < 5dbfcf7b080306b65d9f756fadf46c9495793750, >= 5852b1365df4414523210e444ac7df1dec09acb4, < bce41e4ac6f5ca3b22a07e8cdadc12044bbf9d3b, >= 5852b1365df4414523210e444ac7df1dec09acb4, < d66fea97671fcb516bd6d34bcc033f650ac7ee91, >= 5852b1365df4414523210e444ac7df1dec09acb4, < d9e2585c3bcecb1c83febad31b9f450e93d2509e, >= 5852b1365df4414523210e444ac7df1dec09acb4, < dd80fb2dbf1cd8751efbe4e53e54056f56a9b115CNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
10.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Vendor Advisories (1)

redhatCVE-2022-50828

kernel: clk: zynqmp: Fix stack-out-of-bounds in strncpy`

Dec 30, 2025

References

git.kernel.org / stable/c/0a07b13af04d0db7325018aaa83b5ffe864790c9
git.kernel.org / stable/c/5dbfcf7b080306b65d9f756fadf46c9495793750
git.kernel.org / stable/c/bce41e4ac6f5ca3b22a07e8cdadc12044bbf9d3b
git.kernel.org / stable/c/d66fea97671fcb516bd6d34bcc033f650ac7ee91
git.kernel.org / stable/c/d9e2585c3bcecb1c83febad31b9f450e93d2509e
git.kernel.org / stable/c/dd80fb2dbf1cd8751efbe4e53e54056f56a9b115