Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49331

17
FAUCET Score

CVE-2022-49331 addresses memory leaks within the Linux kernel's NFC subsystem, specifically in the st21nfca driver's EVT_TRANSACTION handling, affecting Linux kernel versions. Rated Medium (CVSS 5.5), this local vulnerability requires low privileges and complexity, potentially leading to a denial of service due to resource exhaustion. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0, < 4.9.318CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.122CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 74th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49331Moderate

kernel: nfc: st21nfca: fix memory leaks in EVT_TRANSACTION handling

Feb 26, 2025

References

git.kernel.org / stable/c/3eca2c42daa4659965db6817479027cbc6df7899
Patch
git.kernel.org / stable/c/54423649bc0ed464b75807a7cf2857a5871f738f
Patch
git.kernel.org / stable/c/55904086041ba4ee4070187b36590f8f8d6df4cd
Patch
git.kernel.org / stable/c/593773088d615a46a42c97e01a0550d192bb7f74
Patch
git.kernel.org / stable/c/6fce324b530dd74750ad870699e33eeed1029ded
Patch
git.kernel.org / stable/c/996419e0594abb311fb958553809f24f38e7abbe
Patch
git.kernel.org / stable/c/d221ce54ce331c1a23be71eebf57f6a088632383
Patch
git.kernel.org / stable/c/db836b97464d44340b568e041fd24602858713f7
Patch
git.kernel.org / stable/c/f444ecd3f57f4ba5090fe8b6756933e37de4226e
Patch