Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49490

17
FAUCET Score

CVE-2022-49490 is a NULL pointer dereference vulnerability in the Linux kernel's drm/msm/mdp5 driver, specifically within the mdp5_pipe_release function. This flaw can lead to a denial of service (DoS) due to an unhandled error return from mdp5_get_global_state when acquiring a modeset lock. Rated Medium severity (CVSS 5.5), it requires local access and low privileges, with no user interaction needed for exploitation. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.18, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.46CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.17.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
18.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 73rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49490

kernel: drm/msm/mdp5: Return error code in mdp5_pipe_release when deadlock is detected

Feb 26, 2025

References

git.kernel.org / stable/c/04bef5f1ba8ea6d7c1c8f5f65e0395c62db59cb8
Patch
git.kernel.org / stable/c/19964dfb39bda4d7716a71009488f0668ecbcf52
Patch
git.kernel.org / stable/c/33dc5aac46e0fad8f5eb193e5906ed0eb6b66ceb
Patch
git.kernel.org / stable/c/49dc28b4b2e28ef7564e355c91487996c1cbebd7
Patch
git.kernel.org / stable/c/776f5c58bfe16cf322d71eeed3c5dda1eeac7e6b
Patch
git.kernel.org / stable/c/b2aa2c4efe93e2580d6a8774b04fe2b99756a322
Patch
git.kernel.org / stable/c/d59be579fa932c46b908f37509f319cbd4ca9a68
Patch