Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49302

17
FAUCET Score

CVE-2022-49302 is a null-pointer dereference vulnerability in the Linux kernel's USB ISP116x host controller driver. This flaw occurs when the platform_get_resource() function returns NULL, leading to a system crash. With a CVSS score of 5.5 (Medium), it can be exploited locally by a low-privileged attacker, resulting in a denial of service (system unavailability). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.318CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.122CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 73rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49302Moderate

kernel: USB: host: isp116x: check return value after calling platform_get_resource()

Feb 26, 2025

References

git.kernel.org / stable/c/134a3408c2d3f7e23eb0e4556e0a2d9f36c2614e
Patch
git.kernel.org / stable/c/3592cfd8b848bf0c4d7740d78a87a7b8f6e1fa9a
Patch
git.kernel.org / stable/c/3825db88d8c704e7992b685618a03f82bffcf2ef
Patch
git.kernel.org / stable/c/7bffda1560a6f255fdf504e059fbbdb5d46b9e44
Patch
git.kernel.org / stable/c/804de302ada3544699c5f48c5314b249af76faa3
Patch
git.kernel.org / stable/c/82a101f14943f479fd190b1e5b40d91c77e2ac1b
Patch
git.kernel.org / stable/c/aca0cab0e9ed33b6371aafb519a6c38f2850ffc3
Patch
git.kernel.org / stable/c/c91a74b1f0f2d2d7e728742ae55e3ffe9ba7853d
Patch
git.kernel.org / stable/c/ee105039d3653444de4d3ede642383c92855dc1e
Patch