boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2022-50015MEDIUM
Linux Linux — ASoC: SOF: Intel: hda-ipc: Do not process IPC reply before firmware boot
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  N  H    5.5   .0018    7.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    febf5da81ea80fa01e141e3ad35526865681418b –  —
  Linux    5.16 –                                      5.19.4
TIMELINE
  Jun 18  Reserved by Linux
  Jun 18  Published (CNA: Linux)
  Aug 15  ENRICHED — CVE-2022-50015 (Linux). Received CVSS 5.5 and CPE data from NVD.
CWE-476 · CNA: Linux · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda-ipc: Do not process IPC reply before firmware boot It is not yet clear, but it is possible to create a firmware so broken that it will send a reply message before a FW_READY message (it is not yet clear if FW_READY will arrive later). Since the reply_data is allocated only after the FW_READY message, this will lead to a NULL pointer dereference if not filtered out. The issue was reported with IPC4 firmware but the same condition is present for IPC3.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 18, 2025ReservedReserved by Linux
June 18, 2025PublishedPublished (CNA: Linux)
August 15, 2026ENRICHEDENRICHED — CVE-2022-50015 (Linux). Received CVSS 5.5 and CPE data from NVD.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinuxfebf5da81ea80fa01e141e3ad35526865681418b
LinuxLinux5.165.19.4

Weaknesses

CWE-476

References (2)

Related

Authoritative record: CVE-2022-50015 at cve.org

Vendors: linux

Weaknesses: CWE-476

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-50015 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.