Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49191

17
FAUCET Score

CVE-2022-49191 is a memory leak vulnerability in the Linux kernel's mxser driver, specifically affecting the xmit_buf in the activate function. This flaw occurs when the Line Status Register (LSR) is 0xff, preventing proper buffer deallocation if activate fails. Rated Medium with a CVSS score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), it primarily poses a denial-of-service risk due to resource exhaustion, requiring local access and low privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.33, < 4.9.311CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.189CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.110CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 74th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49191

kernel: mxser: fix xmit_buf leak in activate when LSR == 0xff

Feb 26, 2025

References

git.kernel.org / stable/c/125b7c929fc9b1e5eaa344bceb6367dfa6fd3f9d
Patch
git.kernel.org / stable/c/2cd05c38a27bee7fb42aa4d43174d68ac55dac0f
Patch
git.kernel.org / stable/c/376922045009f8ea2d20a8fa3475e95b47c41690
Patch
git.kernel.org / stable/c/685b6d16bf89595310b5d61394c9b97cc9505c7c
Patch
git.kernel.org / stable/c/6c9041b2f90c0eace73106f22350e1d2c98f5edc
Patch
git.kernel.org / stable/c/6dffc2035fbaada60ca8db59e0962e34f760370a
Patch
git.kernel.org / stable/c/996291d06851a26678a0fab488b6e1f0677c0576
Patch
git.kernel.org / stable/c/b125b08dbee3611f03f53b71471813ed4ccafcdd
Patch
git.kernel.org / stable/c/cd3a4907ee334b40d7aa880c7ab310b154fd5cd4
Patch