Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49649

17
FAUCET Score

CVE-2022-49649 is a NULL pointer dereference vulnerability in the Linux kernel's Xen netback driver (xen/netback). Specifically, the xenvif_rx_next_skb() function can be called with an empty receive queue, leading to system crashes. This vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.9, < 4.9.324CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.289CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.253CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.207CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.132CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 72nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49649Moderate

kernel: xen/netback: avoid entering xenvif_rx_next_skb() with an empty rx queue

Feb 26, 2025

References

git.kernel.org / stable/c/5a071aefd6414af5a20321ab58a0557b81993687
Patch
git.kernel.org / stable/c/7425479d20f9e96f7c3ec8e8a93fe0d7478724cb
Patch
git.kernel.org / stable/c/94e8100678889ab428e68acadf042de723f094b9
Patch
git.kernel.org / stable/c/b99174ac57fe5d8867448c03b23828e63f24cb1c
Patch
git.kernel.org / stable/c/b9c32a6886af79d6e0ad87a7b01800ed079cdd02
Patch
git.kernel.org / stable/c/c0fcceb5f3f1ec197c014fe218c2f28108cacd27
Patch
git.kernel.org / stable/c/d5320c6a27aa975aff740f9cb481dcbde48f4348
Patch
git.kernel.org / stable/c/f0b5c819b062df8bf5f2acf4697e3871cb3722da
Patch