Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49151

17
FAUCET Score

CVE-2022-49151 is a vulnerability in the Linux kernel's CAN bus driver for MCBA USB devices, specifically affecting the mcba_usb module. The flaw stems from improper endpoint type checking during USB Urban Request Block (URB) submission, potentially leading to a system warning and denial of service. With a CVSS score of 5.5 (Medium), it requires local access and low privileges to exploit, resulting in high availability impact but no confidentiality or integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.12, < 4.14.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.189CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.110CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.33CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 73rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49151

kernel: can: mcba_usb: properly check endpoint type

Feb 26, 2025

References

git.kernel.org / stable/c/136bed0bfd3bc9c95c88aafff2d22ecb3a919f23
Patch
git.kernel.org / stable/c/5598442edc29e8f6f2380e4b471dc1a3fcd80508
Patch
git.kernel.org / stable/c/88272b4a37913bdf6f339162a7920bd8e9b49de2
Patch
git.kernel.org / stable/c/b48d1bb3f1ca337ad653022aefb5a40a47dfe5cd
Patch
git.kernel.org / stable/c/cbd110b8dd7ad763bf413f71c0484116ae9302d4
Patch
git.kernel.org / stable/c/ef0acc514123140157b19a9ff2e2de5d91d612bc
Patch
git.kernel.org / stable/c/f2ec3cd0f34f8c3f94bc21fbba14868301c9c49d
Patch
git.kernel.org / stable/c/fa9c1f14002dc0d5293e16a2007bd89b6e79207b
Patch