Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49335

17
FAUCET Score

CVE-2022-49335 is a kernel NULL pointer dereference vulnerability in the Linux kernel's AMD GPU (amdgpu) driver. Specifically, submitting a command stream (cs) with zero chunks can lead to a system crash (oops) due to an attempt to execute the wrong userspace driver. This affects Linux kernel versions utilizing the amdgpu driver. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity. A successful exploit could lead to a denial of service (system crash), impacting system availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.318CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 75th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49335Moderate

kernel: drm/amdgpu/cs: make commands with 0 chunks illegal behaviour.

Feb 26, 2025

References

git.kernel.org / stable/c/15c3bcc9b5349d40207e5f8d4d799b8b4b7d13b8
Patch
git.kernel.org / stable/c/20b947e5a3c74c5084d661c097517a554989d462
Patch
git.kernel.org / stable/c/31ab27b14daaa75541a415c6794d6f3567fea44a
Patch
git.kernel.org / stable/c/70276460e914d560e96bfc208695a872fe9469c9
Patch
git.kernel.org / stable/c/7086a23890d255bb5761604e39174b20d06231a4
Patch
git.kernel.org / stable/c/8189f44270db1be78169e11eec51a3eeb980bc63
Patch
git.kernel.org / stable/c/aa25acbe96692e4bf8482311c293f72d8c6034c0
Patch
git.kernel.org / stable/c/be585921f29df5422a39c952d188b418ad48ffab
Patch
git.kernel.org / stable/c/c12984cdb077b9042d2dc20ca18cb16a87bcc774
Patch