Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49029

19
FAUCET Score

CVE-2022-49029 is a Use-After-Free (UAF) vulnerability in the Linux kernel's ibmpex hwmon driver. It occurs when ibmpex_register_bmc() fails, leading to a list traversal that can access freed memory. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), this flaw allows a local attacker to achieve high confidentiality, integrity, and availability impacts. There is currently no public exploit code available, and it has received minimal community discussion or media coverage, indicating low active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.24, < 4.9.335CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.301CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.268CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.226CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 49th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-570.12.1.el9_6
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49029Moderate

kernel: hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails

Oct 21, 2024

References

git.kernel.org / stable/c/24b9633f7db7f4809be7053df1d2e117e7c2de10
Patch
git.kernel.org / stable/c/45f6e81863747c0d7bc6a95ec51129900e71467a
Patch
git.kernel.org / stable/c/798198273bf86673b970b51acdb35e57f42b3fcb
Patch
git.kernel.org / stable/c/7b2b67fe1339389e0bf3c37c7a677a004ac0e4e3
Patch
git.kernel.org / stable/c/90907cd4d11351ff76c9a447bcb5db0e264c47cd
Patch
git.kernel.org / stable/c/e2a87785aab0dac190ac89be6a9ba955e2c634f2
Patch
git.kernel.org / stable/c/e65cfd1f9cd27d9c27ee5cb88128a9f79f25d863
Patch
git.kernel.org / stable/c/f2a13196ad41c6c2ab058279dffe6c97292e753a
Patch