Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49304

17
FAUCET Score

CVE-2022-49304 describes a deadlock vulnerability in the Linux kernel's sa1100 serial driver, specifically within the sa1100_set_termios() function. This flaw affects Linux kernel versions and arises when del_timer_sync() attempts to stop a timer while holding a spinlock, which the timer's handler also requires, leading to a permanent block. Rated 5.5 MEDIUM (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), it indicates a local attack with low complexity that can result in high availability impact (denial of service). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.318CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.122CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 48th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49304Moderate

kernel: drivers: tty: serial: Fix deadlock in sa1100_set_termios()

Feb 26, 2025

References

git.kernel.org / stable/c/0976808d0d171ec837d4bd3e9f4ad4a00ab703b8
Patch
git.kernel.org / stable/c/09a5958a2452ad22d0cb638711ef34ea1863a829
Patch
git.kernel.org / stable/c/2cbfc38df580bff5b2fe19f21c1a7520efcc4b3b
Patch
git.kernel.org / stable/c/34d91e555e5582cffdbcbb75517bc9217866823e
Patch
git.kernel.org / stable/c/553213432ef0c295becdc08c0207d2094468f673
Patch
git.kernel.org / stable/c/62b2caef400c1738b6d22f636c628d9f85cd4c4c
Patch
git.kernel.org / stable/c/6e2273eefab54a521d9c59efb6e1114e742bdf41
Patch
git.kernel.org / stable/c/85e20f8bd31a46d8c60103d0274a8ebe8f47f2b2
Patch
git.kernel.org / stable/c/920f0ae7a129ffee98a106e3bbdfd61a2a59e939
Patch