Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49581

21
FAUCET Score

CVE-2022-49581 is a buffer overflow vulnerability in the Linux kernel's be2net driver, specifically within the be_get_module_eeprom function, affecting Linux kernel versions. This flaw arises because the be_cmd_read_port_transceiver_data function incorrectly assumes a minimum buffer size, leading to potential out-of-bounds writes. Rated with a CVSS score of 7.8 (High), it presents a local attack vector with low complexity, allowing an authenticated attacker to achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.18, < 4.9.325CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.290CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.254CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.208CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.134CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 59th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-0:5.14.0-70.163.1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-rt-0:5.14.0-70.163.1.rt21.235.el9_0
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49581Moderate

kernel: Linux kernel: be2net buffer overflow in be_get_module_eeprom

Feb 26, 2025

References

git.kernel.org / stable/c/18043da94c023f3ef09c15017bdb04e8f695ef10
Patch
git.kernel.org / stable/c/665cbe91de2f7c97c51ca8fce39aae26477c1948
Patch
git.kernel.org / stable/c/8ff4f9df73e5c551a72ee6034886c17e8de6596d
Patch
git.kernel.org / stable/c/a5a8fc0679a8fd58d47aa2ebcfc5742631f753f9
Patch
git.kernel.org / stable/c/a8569f76df7ec5b4b51155c57523a0b356db5741
Patch
git.kernel.org / stable/c/aba8ff847f4f927ad7a1a1ee4a9f29989a1a728f
Patch
git.kernel.org / stable/c/d7241f679a59cfe27f92cb5c6272cb429fb1f7ec
Patch
git.kernel.org / stable/c/fe4473fc7940f14c4a12db873b9729134c212654
Patch