Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49429

17
FAUCET Score

CVE-2022-49429 is a null pointer dereference vulnerability in the Linux kernel's hfi1 RDMA module, affecting systems where the HFI1_CAP_SDMA feature is disabled. An attacker with local user privileges can trigger a kernel panic, leading to a denial of service. The vulnerability has a CVSS score of 5.5 (Medium), indicating low attack complexity and no confidentiality or integrity impact, but high availability impact. There is currently no public exploit code, Metasploit modules, or evidence of active exploitation, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.46CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 73rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-477.10.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.11.1.el9_2
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49429Moderate

kernel: RDMA/hfi1: Prevent panic when SDMA is disabled

Feb 26, 2025

References

git.kernel.org / stable/c/0e4dda8b3f4c07ee9ea670a10ea3171a5e63a86f
Patch
git.kernel.org / stable/c/22e7e400fd1a890db2ea13686324aff50e972f4f
Patch
git.kernel.org / stable/c/29952ab85d6c3fe0b7909d9a737f10c58bf6824d
Patch
git.kernel.org / stable/c/32e6aea33944f364d51cd263e4cd236393a188b6
Patch
git.kernel.org / stable/c/33794e8e9bcb4affc0ebff9cdec85acc8b8a1762
Patch
git.kernel.org / stable/c/629e052d0c98e46dde9f0824f0aa437f678d9b8f
Patch
git.kernel.org / stable/c/cc80d3c37cec9d6ddb140483647901bc7cc6c31d
Patch
git.kernel.org / stable/c/e60ad83f645ee6fadd5a8057ba267aeec54f08fe
Patch