Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49155

16
FAUCET Score

CVE-2022-49155 addresses a bug in the Linux kernel's qla2xxx SCSI driver, specifically related to the qla_create_qpair() function. This vulnerability affects Linux kernel versions and could lead to a system crash (denial of service) due to an improper use of smp_processor_id() in preemptible code. Rated as MEDIUM severity (CVSS 5.5), it requires local access and low privileges to exploit, with no user interaction needed. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.189CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.110CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.33CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 74th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49155Low

kernel: scsi: qla2xxx: Suppress a kernel complaint in qla_create_qpair()

Feb 26, 2025

References

git.kernel.org / stable/c/1ab81d82fb1db7ec4be4b0d04563513e6d4bcdd5
Patch
git.kernel.org / stable/c/43195a0c620761fbb88db04e2475313855b948a4
Patch
git.kernel.org / stable/c/8077a7162bc3cf658dd9ff112bc77716c08458c5
Patch
git.kernel.org / stable/c/9c33d49ab9f3d8bd7512b3070cd2f07c4a8849d5
Patch
git.kernel.org / stable/c/a60447e7d451df42c7bde43af53b34f10f34f469
Patch
git.kernel.org / stable/c/a669a22aef0ceff706b885370af74b5a60a8ac85
Patch
git.kernel.org / stable/c/f68776f28d9134fa65056e7e63bfc734049730b7
Patch
git.kernel.org / stable/c/f97316dd393bc8df1cc2af6295a97b876eecf252
Patch