Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49059

20
FAUCET Score

CVE-2022-49059 is a use-after-free vulnerability in the Linux kernel's NFC NCI subsystem, affecting Linux kernel versions. This flaw arises from a race condition during device detachment, where a timer can be re-attached to memory that has already been freed. With a CVSS score of 7.8 (High), it can lead to high impact on confidentiality, integrity, and availability, and is exploitable with low attack complexity and local privileges. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.2, < 4.9.311CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.239CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.112CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 58th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49059Important

kernel: nfc: nci: add flush_workqueue to prevent uaf

Feb 26, 2025

References

git.kernel.org / stable/c/1a1748d0dd0f0a98535c6baeef671c8722107639
Patch
git.kernel.org / stable/c/5c63ad2b0a267a524c12c88acb1ba9c2d109a801
Patch
git.kernel.org / stable/c/67677050cecbe0edfdd81cd508415e9636ba7c65
Patch
git.kernel.org / stable/c/7d3232214ca4ea8f7d18df264c3b254aa8089d7f
Patch
git.kernel.org / stable/c/9d243aff5f7e6b04e907c617426bbdf26e996ac8
Patch
git.kernel.org / stable/c/9ded5ae40f4fe37fcc28f36d76bf45df20be5432
Patch
git.kernel.org / stable/c/edd4600120641e1714e30112e69a548cfb68e067
Patch
git.kernel.org / stable/c/ef27324e2cb7bb24542d6cb2571740eefe6b00dc
Patch