Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49176

20
FAUCET Score

CVE-2022-49176 is a use-after-free vulnerability in the Linux kernel's bfq_dispatch_request function, specifically affecting the BFQ I/O scheduler. This flaw, identified by KASAN during SCSI-MQ testing, could lead to system instability or potentially allow an authenticated local attacker to escalate privileges. With a CVSSv3 score of 7.8 (High), it has low attack complexity and does not require user interaction, posing a significant risk of high confidentiality, integrity, and availability impacts. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.19.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.189CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.110CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.33CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 55th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49176Moderate

kernel: bfq: fix use-after-free in bfq_dispatch_request

Feb 26, 2025

References

git.kernel.org / stable/c/080665e2c3cbfc68359b9a348a3546ed9b908e7a
Patch
git.kernel.org / stable/c/40b4ba0030e0b02cbacd424ebb9f4c8b0976c786
Patch
git.kernel.org / stable/c/5117c9ff4c2ebae0f5c2c262d42a25a8fbc086e6
Patch
git.kernel.org / stable/c/5687958bf18f84384d809f521210d0f5deed03b0
Patch
git.kernel.org / stable/c/74e610b5ee0d95e751280567100509eb11517efa
Patch
git.kernel.org / stable/c/ab552fcb17cc9e4afe0e4ac4df95fc7b30e8490a
Patch
git.kernel.org / stable/c/df6e00b1a53c57dca82c63b5ecbcad5452231bc7
Patch