Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49080

19
FAUCET Score

CVE-2022-49080 is a memory leak vulnerability in the Linux kernel's memory management subsystem, specifically within the mpol_new allocation process during shared memory policy replacement. This flaw can lead to resource exhaustion (denial of service) due to uninitialized reference counts preventing proper deallocation of unused memory policy objects. Rated Medium severity (CVSS 5.5), it requires local access and low privileges to exploit, with low attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.8.1, < 4.9.311CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.189CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.111CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
22.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 79th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-513.5.1.el8_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.11.1.el9_2
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49080Moderate

kernel: mm/mempolicy: fix mpol_new leak in shared_policy_replace

Feb 26, 2025

References

git.kernel.org / stable/c/198932a14aeb19a15cf19e51e151d023bc4cd648
Patch
git.kernel.org / stable/c/25f506273b6ae806fd46bfcb6fdaa5b9ec81a05b
Patch
git.kernel.org / stable/c/39a32f3c06f6d68a530bf9612afa19f50f12e93d
Patch
git.kernel.org / stable/c/4ad099559b00ac01c3726e5c95dc3108ef47d03e
Patch
git.kernel.org / stable/c/5e16dc5378abd749a836daa9ee4ab2c8d2668999
Patch
git.kernel.org / stable/c/6e00309ac716fa8225f0cbde2cd9c24f0e74ee21
Patch
git.kernel.org / stable/c/8510c2346d9e47a72b7f018a36ef0c39483e53d6
Patch
git.kernel.org / stable/c/f7e183b0a7136b6dc9c7b9b2a85a608a8feba894
Patch
git.kernel.org / stable/c/fe39ac59dbbf893b73b24e3184161d0bd06d6651
Patch