Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49348

16
FAUCET Score

CVE-2022-49348 is a medium-severity vulnerability affecting the Linux kernel's ext4 filesystem. A maliciously corrupted superblock can set the EXT4_FC_REPLAY bit in s_mount_state, bypassing sanity checks and triggering a BUG() in ext4_es_cache_extent(). This local vulnerability has a CVSS score of 5.5, indicating low attack complexity and privilege requirements, but high availability impact. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.10, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.46CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.17.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.18, < 5.18.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 76th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-162.6.1.el9_1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49348Moderate

kernel: ext4: filter out EXT4_FC_REPLAY from on-disk superblock field s_state

Feb 26, 2025

References

git.kernel.org / stable/c/55b4dbb29054a05d839562f6d635ce05669b016d
Patch
git.kernel.org / stable/c/af2f1932743fb52ebcb008ad7ac500d9df0aa796
Patch
git.kernel.org / stable/c/b99fd73418350dea360da8311e87a6a7b0e15a4c
Patch
git.kernel.org / stable/c/c878bea3c9d724ddfa05a813f30de3d25a0ba83f
Patch
git.kernel.org / stable/c/cc5b09cb6dacd4b32640537929ab4ee8fb2b9e04
Patch