Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49032

19
FAUCET Score

CVE-2022-49032 is an out-of-bounds read vulnerability in the Linux kernel's afe4404 IIO health driver, affecting Linux kernel versions. This flaw, identified as CWE-125, allows a local attacker to read sensitive information and potentially cause a denial of service by accessing array elements beyond their defined boundaries. With a CVSS v3.1 score of 7.1 (HIGH), it has low attack complexity and requires local privileges, but could lead to high confidentiality and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.8, < 4.9.335CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.301CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.268CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.226CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 49th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49032Moderate

kernel: iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw

Oct 21, 2024

References

git.kernel.org / stable/c/113c08030a89aaf406f8a1d4549d758a67c2afba
Patch
git.kernel.org / stable/c/3f566b626029ca8598d48e5074e56bb37399ca1b
Patch
git.kernel.org / stable/c/5eb114f55b37dbc0487aa9c1913b81bb7837f1c4
Patch
git.kernel.org / stable/c/68de7da092f38395dde523f2e5db26eba6c23e28
Patch
git.kernel.org / stable/c/d45d9f45e7b1365fd0d9bf14680d6d5082a590d1
Patch
git.kernel.org / stable/c/f5575041ec15310bdc50c42b8b22118cc900226e
Patch
git.kernel.org / stable/c/f7419fc42afc035f6b29ce713e17dcd2000c833f
Patch
git.kernel.org / stable/c/fc92d9e3de0b2d30a3ccc08048a5fad533e4672b
Patch