Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49293

17
FAUCET Score

CVE-2022-49293 is a medium-severity vulnerability in the Linux kernel's netfilter component, specifically within the nft_do_chain() function. This flaw, rated 5.5 CVSSv3.1, involves a lack of register initialization, which could lead to a stack leak into user space. While the attack requires local access and user interaction is not needed, a successful exploit could result in a high impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.13, < 4.9.309CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.274CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.237CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.188CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.109CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 77th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49293Moderate

kernel: netfilter: nf_tables: initialize registers in nft_do_chain()

Feb 26, 2025

References

git.kernel.org / stable/c/06f0ff82c70241a766a811ae1acf07d6e2734dcb
Patch
git.kernel.org / stable/c/2c74374c2e88c7b7992bf808d9f9391f7452f9d9
Patch
git.kernel.org / stable/c/4c905f6740a365464e91467aa50916555b28213d
Patch
git.kernel.org / stable/c/4d28522acd1c4415c85f6b33463713a268f68965
Patch
git.kernel.org / stable/c/64f24c76dd0ce53d0fa3a0bfb9aeea507c769485
Patch
git.kernel.org / stable/c/88791b79a1eb2ba94e95d039243e28433583a67b
Patch
git.kernel.org / stable/c/a3cc32863b175168283cb0a5fde08de6a1e27df9
Patch
git.kernel.org / stable/c/dd03640529204ef4b8189fbdea08217d8d98271f
Patch
git.kernel.org / stable/c/fafb904156fbb8f1dd34970cd5223e00b47c33be
Patch