Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49017

21
FAUCET Score

CVE-2022-49017 is a use-after-free vulnerability in the Linux kernel's TIPC module, specifically within the tipc_crypto_rcv_complete function. This flaw occurs because the skb (socket buffer) control block is dereferenced after the original skb has been freed by tipc_msg_validate(), leading to a system crash. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), it allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.5, < 5.10.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.82CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.0.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*
6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 50th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49017Moderate

kernel: tipc: re-fetch skb cb after tipc_msg_validate

Oct 21, 2024

References

git.kernel.org / stable/c/1daec0815655e110c6f206c5e777a4af8168ff58
Patch
git.kernel.org / stable/c/3067bc61fcfe3081bf4807ce65560f499e895e77
Patch
git.kernel.org / stable/c/a1ba595e35aa3afbe417ff0af353afb9f65559c0
Patch
git.kernel.org / stable/c/e128190adb2edfd5042105b5d1ed4553f295f5ef
Patch