Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49554

15
FAUCET Score

CVE-2022-49554 is a race condition vulnerability in the Linux kernel's zsmalloc component, specifically affecting the asynchronous zspage free worker. This flaw allows for unsafe dereferencing and potential data corruption due to inadequate synchronization with page migration. Rated as MEDIUM severity (CVSS 4.7), it requires local access and high attack complexity to achieve a high impact on availability. There is currently no evidence of active exploitation, nor are there public exploits or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.14, < 4.14.282CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.246CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.197CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.120CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.45CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 48th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49554Low

kernel: zsmalloc: fix races between asynchronous zspage free and page migration

Feb 26, 2025

References

git.kernel.org / stable/c/2505a981114dcb715f8977b8433f7540854851d8
Patch
git.kernel.org / stable/c/3674d8a8dadd03a447dd21069d4dacfc3399b63b
Patch
git.kernel.org / stable/c/3ec459c8810e658401be428d3168eacfc380bdd0
Patch
git.kernel.org / stable/c/645996efc2ae391246d595832aaa6f9d3cc338c7
Patch
git.kernel.org / stable/c/8ba7b7c1dad1f6503c541778f31b33f7f62eb966
Patch
git.kernel.org / stable/c/c5402fb5f71f1a725f1e55d9c6799c0c7bec308f
Patch
git.kernel.org / stable/c/fae05b2314b147a78fbed1dc4c645d9a66313758
Patch
git.kernel.org / stable/c/fc658c083904427abbf8f18280d517ee2668677c
Patch