Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49112

18
FAUCET Score

CVE-2022-49112 addresses a kernel crash in the Linux kernel's mt76 wireless driver, specifically impacting devices using the mt7921s SDIO driver in monitor mode. The vulnerability arises from improper handling of fragmented frames, leading to a BUG_ON condition during skb_pull() operations. With a CVSS score of 5.5 MEDIUM, this local attack requires low privileges and has a high impact on availability, potentially causing a denial of service. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.16, < 5.15.34CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.20CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.17, < 5.17.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 66th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49112

kernel: mt76: fix monitor mode crash with sdio driver

Feb 26, 2025

References

git.kernel.org / stable/c/123bc712b1de0805f9d683687e17b1ec2aba0b68
Patch
git.kernel.org / stable/c/13946d5a68efd11dd6af2f6ef4c908f6b00158a5
Patch
git.kernel.org / stable/c/95e2af01669c7a3cb7a933cefa06361f9db15059
Patch
git.kernel.org / stable/c/c37b4cab3d97ef64b206fca4d9daabd9aff7356e
Patch