Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49340

17
FAUCET Score

CVE-2022-49340 is a medium-severity vulnerability in the Linux kernel's ip_gre module, specifically related to how Generic Routing Encapsulation (GRE) handles checksum offloading. The flaw could lead to a denial-of-service (DoS) condition if an attacker can trigger an overflow during the checksum validation process. The vulnerability has a CVSS score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating that local access with low privileges is required, and the primary impact is high availability loss. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19.207, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.148, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.68, < 5.10.122CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.14.7, < 5.15.47CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.17.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 75th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-162.6.1.el9_1
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49340Low

kernel: ip_gre: test csum_start instead of transport header

Feb 26, 2025

References

git.kernel.org / stable/c/0c92d813c7c9ca2212ecd879232e7d87362fce98
Patch
git.kernel.org / stable/c/0ffa268724656633af5f37a38c212326d98ebe8c
Patch
git.kernel.org / stable/c/3d08bc3a5d9b2106f5c8bcf1adb73147824aa006
Patch
git.kernel.org / stable/c/7596bd7920985f7fc8579a92e48bc53ce4475b21
Patch
git.kernel.org / stable/c/8d21e9963bec1aad2280cdd034c8993033ef2948
Patch
git.kernel.org / stable/c/e6b6f98fc7605c06c0a3baa70f62c534d7b4ce58
Patch
git.kernel.org / stable/c/fbeb8dfa8b87ef259eef0c89e39b53962a3cf604
Patch