Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49290

21
FAUCET Score

CVE-2022-49290 is a double-free vulnerability in the Linux kernel's mac80211 component, specifically affecting mesh networking functionality. This flaw, rated High severity (CVSS 7.8), can lead to memory corruption and kernel panics when rejoining a mesh network after leaving it, particularly when not using wpa_supplicant. While not actively exploited in the wild, the vulnerability allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. There is no public exploit code, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.4.233, < 4.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.9.233, < 4.9.309CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.14.192, < 4.14.274CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.19.137, < 4.19.237CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.56, < 5.4.188CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 51st percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-425.3.1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-305.184.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: kernel-0:4.18.0-305.184.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-372.177.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-372.177.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-372.177.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-162.6.1.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-0:5.14.0-70.163.1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-rt-0:5.14.0-70.163.1.rt21.235.el9_0
View patch

Vendor Advisories (1)

redhatCVE-2022-49290Moderate

kernel: mac80211: fix potential double free on mesh join

Feb 26, 2025

References

git.kernel.org / stable/c/12e407a8ef17623823fd0c066fbd7f103953d28d
Patch
git.kernel.org / stable/c/273ebddc5fda2967492cb0b6cdd7d81cfb821b76
Patch
git.kernel.org / stable/c/3bbd0000d012f92aec423b224784fbf0f7bf40f8
Patch
git.kernel.org / stable/c/46bb87d40683337757a2f902fcd4244b32bb4e86
Patch
git.kernel.org / stable/c/4a2d4496e15ea5bb5c8e83b94ca8ca7fb045e7d3
Patch
git.kernel.org / stable/c/582d8c60c0c053684f7138875e8150d5749ffc17
Patch
git.kernel.org / stable/c/5d3ff9542a40ce034416bca03864709540a36016
Patch
git.kernel.org / stable/c/615716af8644813355e014314a0bc1e961250f5a
Patch
git.kernel.org / stable/c/c1d9c3628ef0a0ca197595d0f9e01cd3b5dda186
Patch