Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49489

21
FAUCET Score

CVE-2022-49489 is a use-after-free vulnerability in the Linux kernel's Display Processing Unit (DPU) driver, specifically affecting the drm/msm/disp/dpu1 component. This flaw can lead to a kernel paging request error during power management runtime resume operations. Rated with a CVSS score of 7.8 (High), it allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, nor is there any evidence of active exploitation or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.46CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.17.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 56th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49489Moderate

kernel: drm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resume

Feb 26, 2025

References

git.kernel.org / stable/c/134760263f6441741db0b2970e7face6b34b6d1c
Patch
git.kernel.org / stable/c/5b0adf5cbf3b74721e4e4c4e0cadc91b8df8bcc2
Patch
git.kernel.org / stable/c/97ac682b6f7d36be5d934f86c9911066540a68f1
Patch
git.kernel.org / stable/c/aa4cb188988dc6f1b3f4917d4dbc452150a5d871
Patch
git.kernel.org / stable/c/ef10d0c68e8608848cd58fca2589685718426607
Patch
git.kernel.org / stable/c/ef4bdaac7cb5416f236613ed9337ff0ea8ee329b
Patch
git.kernel.org / stable/c/fa5186b279ecf44b14fb435540d2065be91cb1ed
Patch