Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49367

17
FAUCET Score

CVE-2022-49367 is a refcount leak vulnerability in the Linux kernel's mv88e6xxx Ethernet switch driver, specifically within the mv88e6xxx_mdios_register function. This flaw, affecting Linux kernel versions, stems from a missing of_node_put() call after of_get_child_by_name(), leading to resource exhaustion. Rated Medium severity (CVSS 5.5), it requires local access (AV:L, PR:L) and could result in a denial-of-service (A:H) due to memory leaks. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.11, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.122CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.47CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 73rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49367Moderate

kernel: net: dsa: mv88e6xxx: Fix refcount leak in mv88e6xxx_mdios_register

Feb 26, 2025

References

git.kernel.org / stable/c/02ded5a173619b11728b8bf75a3fd995a2c1ff28
Patch
git.kernel.org / stable/c/42658e47f1abbbe592007d3ba303de466114d0bb
Patch
git.kernel.org / stable/c/86c3c5f8e4bd1325e24f6fba9017cade29933377
Patch
git.kernel.org / stable/c/8a1a1255152da4fb934290e7ababc66f24985520
Patch
git.kernel.org / stable/c/a101793994c0a14c70bb4e44c7fda597eeebba0a
Patch
git.kernel.org / stable/c/c1df9cb756e5a9ba1841648c44ee5d92306b9c65
Patch
git.kernel.org / stable/c/dc1cf8c6f9793546696fded437a5b4c84944c48b
Patch
git.kernel.org / stable/c/e0d763d0c7665c7897e4f5a0847ab0c82543345f
Patch