Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49015

21
FAUCET Score

CVE-2022-49015 is a high-severity use-after-free vulnerability in the Linux kernel's High-availability Seamless Redundancy (HSR) networking component. An attacker with local access could exploit this flaw to achieve high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability's nature (CWE-416) indicates a significant risk if exploited.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.13, < 4.9.335CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.301CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.268CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.226CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 51st percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49015Moderate

kernel: net: hsr: Fix potential use-after-free

Oct 21, 2024

References

git.kernel.org / stable/c/4b351609af4fdbc23f79ab2b12748f4403ea9af4
Patch
git.kernel.org / stable/c/53a62c5efe91665f7a41fad0f888a96f94dc59eb
Patch
git.kernel.org / stable/c/7ca81a161e406834a1fdc405fc83a572bd14b8d9
Patch
git.kernel.org / stable/c/7e177d32442b7ed08a9fa61b61724abc548cb248
Patch
git.kernel.org / stable/c/8393ce5040803666bfa26a3a7bf41e44fab0ace9
Patch
git.kernel.org / stable/c/b35d899854d5d5d58eb7d7e7c0f61afc60d3a9e9
Patch
git.kernel.org / stable/c/dca370e575d9b6c983f5015e8dc035e23e219ee6
Patch
git.kernel.org / stable/c/f3add2b8cf620966de3ebfa07679ca12d33ec26f
Patch