Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49448

17
FAUCET Score

CVE-2022-49448 is a null pointer dereference vulnerability in the Linux kernel's Broadcom SoC driver, affecting Linux kernel versions. This medium-severity vulnerability (CVSS 5.5) allows a local attacker with low privileges to cause a denial of service (system crash) due to a missing null check after a memory allocation failure. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.12, < 5.15.46CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.17.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.18, < 5.18.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 71st percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49448Moderate

kernel: soc: bcm: Check for NULL return of devm_kzalloc()

Feb 26, 2025

References

git.kernel.org / stable/c/36339ea7bae4943be01c8e9545e46e334591fecd
Patch
git.kernel.org / stable/c/5650e103bfc70156001615861fb8aafb3947da6e
Patch
git.kernel.org / stable/c/b48b98743b568bb219152ba2e15af6ef0d3d8a9b
Patch
git.kernel.org / stable/c/b4bd2aafacce48db26b0a213d849818d940556dd
Patch