Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49019

17
FAUCET Score

CVE-2022-49019 is a NULL pointer dereference vulnerability in the Linux kernel's nixge Ethernet driver, specifically affecting the nixge_hw_dma_bd_release() function. This flaw occurs if memory allocation for priv->rx_bd_v fails, leading to a system crash. Rated Medium (CVSS 5.5), it requires local access and low privileges to exploit, resulting in a high impact on availability (denial of service). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.17, < 5.4.226CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.82CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.0.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.1CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 63rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49019Moderate

kernel: net: ethernet: nixge: fix NULL dereference

Oct 21, 2024

References

git.kernel.org / stable/c/45752af0247589e6d3dede577415bfe117b4392c
Patch
git.kernel.org / stable/c/80e82f7b440b65cf131dce10f487dc73a7046e6b
Patch
git.kernel.org / stable/c/910c0264b64ef2dad8887714a7c56c93e39a0ed3
Patch
git.kernel.org / stable/c/9256db4e45e8b497b0e993cc3ed4ad08eb2389b6
Patch
git.kernel.org / stable/c/9c584d6d9cfb935dce8fc81a4c26debac0a3049b
Patch