CVE-2022-50174

MEDIUMNVD 5.55.5
EchelonGraph scoreMEDIUM confidence

Score 5.5 from GitHub Security Advisory published 2025-06-18. NVD baseline CVSS 5.5; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
5.5
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS: 0%CVSS: 5.5Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

net: hinic: avoid kernel hung in hinic_get_stats64()

When using hinic device as a bond slave device, and reading device stats of master bond device, the kernel may hung.

The kernel panic calltrace as follows: Kernel panic - not syncing: softlockup: hung tasks Call trace: native_queued_spin_lock_slowpath+0x1ec/0x31c dev_get_stats+0x60/0xcc dev_seq_printf_stats+0x40/0x120 dev_seq_show+0x1c/0x40 seq_read_iter+0x3c8/0x4dc seq_read+0xe0/0x130 proc_reg_read+0xa8/0xe0 vfs_read+0xb0/0x1d4 ksys_read+0x70/0xfc __arm64_sys_read+0x20/0x30 el0_svc_common+0x88/0x234 do_el0_svc+0x2c/0x90 el0_svc+0x1c/0x30 el0_sync_handler+0xa8/0xb0 el0_sync+0x148/0x180

And the calltrace of task that actually caused kernel hungs as follows: __switch_to+124 __schedule+548 schedule+72 schedule_timeout+348 __down_common+188 __down+24 down+104 hinic_get_stats64+44 [hinic] dev_get_stats+92 bond_get_stats+172 [bonding] dev_get_stats+92 dev_seq_printf_stats+60 dev_seq_show+24 seq_read_iter+964 seq_read+220 proc_reg_read+164 vfs_read+172 ksys_read+108 __arm64_sys_read+28 el0_svc_common+132 do_el0_svc+40 el0_svc+24 el0_sync_handler+164 el0_sync+324

When getting device stats from bond, kernel will call bond_get_stats(). It first holds the spinlock bond->stats_lock, and then call hinic_get_stats64() to collect hinic device's stats. However, hinic_get_stats64() calls down(&nic_dev->mgmt_lock) to protect its critical section, which may schedule current task out. And if system is under high pressure, the task cannot be woken up immediately, which eventually triggers kernel hung panic.

Since previous patch has replaced hinic_dev.tx_stats/rx_stats with local variable in hinic_get_stats64(), there is nothing need to be protected by lock, so just removing down()/up() is ok.

CVSS v3
5.5
EG Score
5.5(medium)
EG Risk
29(Track)
EG Risk 29/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity55% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS
4.9%
KEV
Not listed

Published

June 18, 2025

Last Modified

November 28, 2025

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 14× in last 7d / 48× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-23 02:17 UTCEG score recompute
  2. 2026-07-22 23:04 UTCEG score recompute
  3. 2026-07-22 14:06 UTCEPSS rescore
  4. 2026-07-22 14:06 UTCEPSS rescore
  5. 2026-07-21 15:23 UTCEPSS rescore
  6. 2026-07-21 15:23 UTCEPSS rescore
  7. 2026-07-20 17:05 UTCEPSS rescore
  8. 2026-07-19 14:29 UTCEPSS rescore
  9. 2026-07-19 14:29 UTCEPSS rescore
  10. 2026-07-19 02:27 UTCEPSS rescore
  11. 2026-07-19 02:27 UTCEPSS rescore
  12. 2026-07-18 10:03 UTCEPSS rescore
  13. 2026-07-18 10:03 UTCEPSS rescore
  14. 2026-07-16 17:00 UTCEPSS rescore
  15. 2026-07-15 16:56 UTCEPSS rescore
  16. 2026-07-15 16:56 UTCEPSS rescore
  17. 2026-07-15 01:58 UTCEPSS rescore
  18. 2026-07-15 01:58 UTCEPSS rescore
  19. 2026-07-13 22:28 UTCEPSS rescore
  20. 2026-07-13 22:28 UTCEPSS rescore
  21. 2026-07-13 06:11 UTCEPSS rescore
  22. 2026-07-13 06:11 UTCEPSS rescore
  23. 2026-07-12 05:44 UTCEPSS rescore
  24. 2026-07-11 08:25 UTCEPSS rescore
  25. 2026-07-11 08:25 UTCEPSS rescore
Show 66 more
  1. 2026-07-09 19:08 UTCEPSS rescore
  2. 2026-07-08 15:13 UTCEPSS rescore
  3. 2026-07-07 13:44 UTCEPSS rescore
  4. 2026-07-06 21:34 UTCOSV refresh
  5. 2026-07-06 16:25 UTCEPSS rescore
  6. 2026-07-06 02:21 UTCEPSS rescore
  7. 2026-07-05 02:28 UTCEPSS rescore
  8. 2026-07-04 06:29 UTCEPSS rescore
  9. 2026-07-01 15:04 UTCEPSS rescore
  10. 2026-06-30 23:21 UTCEPSS rescore
  11. 2026-06-30 23:20 UTCEPSS rescore
  12. 2026-06-29 14:04 UTCEPSS rescore
  13. 2026-06-28 14:06 UTCEPSS rescore
  14. 2026-06-28 04:54 UTCEPSS rescore
  15. 2026-06-28 04:54 UTCEPSS rescore
  16. 2026-06-27 03:07 UTCEPSS rescore
  17. 2026-06-27 03:07 UTCEPSS rescore
  18. 2026-06-25 13:48 UTCEPSS rescore
  19. 2026-06-25 13:48 UTCEPSS rescore
  20. 2026-06-24 14:03 UTCEPSS rescore
  21. 2026-06-24 14:03 UTCEPSS rescore
  22. 2026-06-23 21:31 UTCEPSS rescore
  23. 2026-06-23 21:31 UTCEPSS rescore
  24. 2026-06-22 14:24 UTCEPSS rescore
  25. 2026-06-21 14:55 UTCEPSS rescore
  26. 2026-06-21 14:55 UTCEPSS rescore
  27. 2026-06-21 01:58 UTCEPSS rescore
  28. 2026-06-21 01:58 UTCEPSS rescore
  29. 2026-06-19 19:24 UTCEPSS rescore
  30. 2026-06-19 19:24 UTCEPSS rescore
  31. 2026-06-18 17:51 UTCEPSS rescore
  32. 2026-06-18 17:51 UTCEPSS rescore
  33. 2026-06-18 09:13 UTCOSV refresh
  34. 2026-06-17 17:51 UTCEPSS rescore
  35. 2026-06-17 17:51 UTCEPSS rescore
  36. 2026-06-16 17:51 UTCEPSS rescore
  37. 2026-06-16 17:51 UTCEPSS rescore
  38. 2026-06-15 17:47 UTCEPSS rescore
  39. 2026-06-14 23:16 UTCEPSS rescore
  40. 2026-06-13 22:59 UTCEPSS rescore
  41. 2026-06-12 23:10 UTCEPSS rescore
  42. 2026-06-12 23:10 UTCEPSS rescore
  43. 2026-06-11 13:58 UTCEPSS rescore
  44. 2026-06-11 13:58 UTCEPSS rescore
  45. 2026-06-10 13:21 UTCEPSS rescore
  46. 2026-06-10 13:21 UTCEPSS rescore
  47. 2026-06-08 14:15 UTCEPSS rescore
  48. 2026-06-08 14:15 UTCEPSS rescore
  49. 2026-06-07 15:23 UTCEPSS rescore
  50. 2026-06-07 15:23 UTCEPSS rescore
  51. 2026-06-06 13:46 UTCEPSS rescore
  52. 2026-06-06 13:46 UTCEPSS rescore
  53. 2026-06-05 22:46 UTCEPSS rescore
  54. 2026-06-05 22:46 UTCEPSS rescore
  55. 2026-06-05 06:09 UTCEPSS rescore
  56. 2026-06-05 06:09 UTCEPSS rescore
  57. 2026-06-04 13:11 UTCEPSS rescore
  58. 2026-06-01 13:50 UTCEPSS rescore
  59. 2026-06-01 13:50 UTCEPSS rescore
  60. 2026-05-31 22:29 UTCEPSS rescore
  61. 2026-05-31 22:29 UTCEPSS rescore
  62. 2026-05-31 00:15 UTCEPSS rescore
  63. 2026-05-31 00:15 UTCEPSS rescore
  64. 2026-05-30 03:13 UTCEG score recompute
  65. 2026-05-30 03:13 UTCGHSA enrichment
  66. 2026-05-29 13:43 UTCEPSS rescore

Frequently asked(5)

What is CVE-2022-50174?
CVE-2022-50174 is a medium vulnerability published on June 18, 2025. In the Linux kernel, the following vulnerability has been resolved: net: hinic: avoid kernel hung in hinicgetstats64() When using hinic device as a bond slave device, and reading device stats of master bond device, the kernel may hung. The kernel panic calltrace as follows: Kernel panic - not…
When was CVE-2022-50174 disclosed?
CVE-2022-50174 was first published in the National Vulnerability Database on June 18, 2025, with the most recent update on November 28, 2025. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2022-50174 actively exploited?
CVE-2022-50174 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 4.9% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2022-50174?
CVE-2022-50174 has a CVSS v3 base score of 5.5 (NVD).
How do I remediate CVE-2022-50174?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2022-50174, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2022-50174

Explore →

Is Your Infrastructure Affected by CVE-2022-50174?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.