Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49052

17
FAUCET Score

CVE-2022-49052 is a vulnerability in the Linux kernel's memory management, specifically affecting zram swap functionality. It allows a user process to unexpectedly read zeroed data due to a race condition during page swapping when processes are cloned with CLONE_VM. This can lead to data corruption within the user process. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (A:H) without affecting confidentiality or integrity. The root cause was an issue with swap_slot_free_notify not properly managing swap slot refcounts in CLONE_VM scenarios. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.15, < 4.19.242CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.193CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.112CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.35CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.17.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 76th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49052Moderate

kernel: mm: fix unexpected zeroed page mapping with zram swap

Feb 26, 2025

References

git.kernel.org / stable/c/12ba1d38115a101c45d8e0ca3aa1181fd148e57f
Patch
git.kernel.org / stable/c/20ed94f8181a25212e7404e44958e234f407624b
Patch
git.kernel.org / stable/c/afac4b88699a06c8b9369f9d759a1ec3c254b788
Patch
git.kernel.org / stable/c/e914d8f00391520ecc4495dd0ca0124538ab7119
Patch
git.kernel.org / stable/c/f098f8b9820fe3f2e41aefc4329dfe8a3859d1c1
Patch
git.kernel.org / stable/c/f86d55cf616199404c05f5b0c5c41b17351baa02
Patch