Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49677

17
FAUCET Score

CVE-2022-49677 is a refcount leak vulnerability in the Linux kernel's ARM cns3xxx driver, specifically affecting the linux_kernel product. This local vulnerability has medium severity (CVSS 5.5), requiring low privileges and no user interaction, and could lead to a denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.10, < 4.9.321CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.286CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.250CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.202CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.127CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 70th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49677Moderate

kernel: ARM: cns3xxx: Fix refcount leak in cns3xxx_init

Feb 26, 2025

References

git.kernel.org / stable/c/1ba904b6b16e08de5aed7c1349838d9cd0d178c5
Patch
git.kernel.org / stable/c/45bebbc8cea7d586a6216dc62814bdb380b9b29b
Patch
git.kernel.org / stable/c/68d4303bf59662b64bd555e2aa0518282d20aa4f
Patch
git.kernel.org / stable/c/b8b84e01ca94e2e1f5492353e9c24dab520b2e5b
Patch
git.kernel.org / stable/c/c980392af1473d6d5662f70d8089c8e6d85144a4
Patch
git.kernel.org / stable/c/d1359e4129ad43e43972a28838b87291c51de23d
Patch
git.kernel.org / stable/c/da3ee7cd2f15922ad88a7ca6deee2eafdc7cd214
Patch
git.kernel.org / stable/c/dc5170aae24e04068fd5ea125d06c0ab51f48a27
Patch