Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49089

15
FAUCET Score

CVE-2022-49089 is a race condition vulnerability in the Linux kernel's RDMA Virtual Transport (RDMAvt) component. This flaw arises because a critical function call, rvt_error_qp, was inadvertently made outside of its required lock protection, potentially leading to system instability. With a CVSS score of 4.7 (Medium), successful exploitation requires local access and high attack complexity, primarily impacting system availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0.4, < 5.4.189CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.111CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.34CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.20CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.17, < 5.17.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 35th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49089Moderate

kernel: IB/rdmavt: add lock to call to rvt_error_qp to prevent a race condition

Feb 26, 2025

References

git.kernel.org / stable/c/43c2d7890ecabe527448a6c391fb2d9a5e6bbfe0
Patch
git.kernel.org / stable/c/4d809f69695d4e7d1378b3a072fa9aef23123018
Patch
git.kernel.org / stable/c/57800cc36e55db0547461c49acf5cd84c0f502b0
Patch
git.kernel.org / stable/c/77ffb2495a41098f9d6a14f8aefde3188da75944
Patch
git.kernel.org / stable/c/8a50937227c385a477177c9ffa122b4230e40666
Patch
git.kernel.org / stable/c/92f1947c0d26060e978b3a9f21f32ce7c8c9cca3
Patch