Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49681

17
FAUCET Score

CVE-2022-49681 is a refcount leak bug in the Linux kernel's Xtensa FPGA setup function, specifically affecting the xtensa:xtfpga component. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and potentially leading to a high availability impact. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.321CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.286CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.250CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.202CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.127CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 70th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49681Moderate

kernel: xtensa: xtfpga: Fix refcount leak bug in setup

Feb 26, 2025

References

git.kernel.org / stable/c/0162451723178602c37f0555d235dfa17e486112
Patch
git.kernel.org / stable/c/0715d0e60052662c3f225342062f174dd721d1c7
Patch
git.kernel.org / stable/c/173940b3ae40114d4179c251a98ee039dc9cd5b3
Patch
git.kernel.org / stable/c/35d7e961be68732eb3acaeba81fb81ca16eafd05
Patch
git.kernel.org / stable/c/6c0839cf1b9e1b3c88da6af76794583cbfae8da3
Patch
git.kernel.org / stable/c/9b30c5c8884eda3f541229899671cebbad15979b
Patch
git.kernel.org / stable/c/a52972ee706b438302eb0350e61f378eb191e3d1
Patch
git.kernel.org / stable/c/b12d5c52f073a0420622aaf2f21b615cce8b36cc
Patch