Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49321

17
FAUCET Score

CVE-2022-49321 is a NULL pointer dereference vulnerability in the Linux kernel's xprtrdma module, specifically affecting NFSv3 clients. When an RDMA server returns a fault format reply and the bc_serv is NULL, the client may incorrectly interpret it as a bcall, leading to a kernel crash. This vulnerability has a CVSSv3.1 score of 5.5 MEDIUM, indicating a local attack vector with low complexity, requiring local privileges, and resulting in high availability impact (system crash). There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.122CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.47CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 76th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-362.8.1.el9_3
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49321Moderate

kernel: xprtrdma: treat all calls not a bcall when bc_serv is NULL

Feb 26, 2025

References

git.kernel.org / stable/c/11270e7ca268e8d61b5d9e5c3a54bd1550642c9c
Patch
git.kernel.org / stable/c/8dbae5affbdbf524b48000f9d357925bb001e5f4
Patch
git.kernel.org / stable/c/8e3943c50764dc7c5f25911970c3ff062ec1f18c
Patch
git.kernel.org / stable/c/90c4f73104016748533a5707ecd15930fbeff402
Patch
git.kernel.org / stable/c/91784f3d77b73885e1b2e6b59d3cbf0de0a1126a
Patch
git.kernel.org / stable/c/998d35a2aff4b81a1c784f3aa45cd3afff6814c1
Patch
git.kernel.org / stable/c/a3fc8051ee061e31db13e2fe011e8e0b71a7f815
Patch
git.kernel.org / stable/c/da99331fa62131a38a0947a8204c5208de7b0454
Patch