Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49503

19
FAUCET Score

CVE-2022-49503 is a Linux kernel vulnerability affecting the ath9k_htc wireless driver, where an out-of-bounds access can occur due to an invalid rxstatus->rs_keyix value being passed to test_bit(). This vulnerability is rated High severity (CVSS 7.1) with a local attack vector, low attack complexity, and potential for high confidentiality impact and high availability impact. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.15, < 4.9.318CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.247CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 55th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-0:5.14.0-70.165.1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-rt-0:5.14.0-70.165.1.rt21.237.el9_0
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2022-49503Moderate

kernel: Linux kernel: ath9k_htc out-of-bounds access vulnerability

Feb 26, 2025

References

git.kernel.org / stable/c/0bcb528402cd5e1a6e1833e956fd58a12d509e8e
Patch
git.kernel.org / stable/c/2326d398ccd41ba6d93b8346532dfa432ab00fee
Patch
git.kernel.org / stable/c/2dc509305cf956381532792cb8dceef2b1504765
Patch
git.kernel.org / stable/c/3dad3fed5672828c7fb0465cb66a3d9a70952fa6
Patch
git.kernel.org / stable/c/461e4c1f199076275f16bf6f3d3e42c6b6c79f33
Patch
git.kernel.org / stable/c/4bdcf32c965c27f55ccc4ee71c1927131115b0bb
Patch
git.kernel.org / stable/c/7f6defe0fabc79f29603c6fa3c80e4fe0456a3e9
Patch
git.kernel.org / stable/c/a048e0c3caa852397b7b50d4c82a0415c05f7ac3
Patch
git.kernel.org / stable/c/eda518db7db16c360bc84379d90675650daa3048
Patch