Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49337

17
FAUCET Score

CVE-2022-49337 is a vulnerability in the Linux kernel's OCFS2 Distributed Lock Manager (DLM) filesystem, specifically affecting the handling of user_dlm_destroy_lock. This flaw can lead to a use-after-free condition and subsequent kernel panic. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (system crash). It is categorized as CWE-667 (Improper Locking). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been observed for this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.318CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 48th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49337

kernel: ocfs2: dlmfs: fix error handling of user_dlm_destroy_lock

Feb 26, 2025

References

git.kernel.org / stable/c/02480e2e82ae0e5588374bbbcf4fa6e4959fa174
Patch
git.kernel.org / stable/c/1434cd71ad9f3a6beda3036972983b6c4869207c
Patch
git.kernel.org / stable/c/2c5e26a626fe46675bceba853e12aaf13c712e10
Patch
git.kernel.org / stable/c/337e36550788dbe03254f0593a231c1c4873b20d
Patch
git.kernel.org / stable/c/733a35c00ef363a1c774d7ea486e0735b7c13a15
Patch
git.kernel.org / stable/c/82bf8e7271fade40184177cb406203addc34c4a0
Patch
git.kernel.org / stable/c/863e0d81b6683c4cbc588ad831f560c90e494bef
Patch
git.kernel.org / stable/c/9c96238fac045b289993d7bc5aae7b2d72b25c76
Patch
git.kernel.org / stable/c/efb54ec548829e1d3605f0434526f86e345b1b28
Patch