Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49682

17
FAUCET Score

CVE-2022-49682 is a refcount leak bug in the Linux kernel's Xtensa architecture, specifically within the calibrate_ccount() function in time.c, affecting Linux kernel versions. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and resulting in high availability impact without affecting confidentiality or integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.321CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.286CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.250CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.202CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.127CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 70th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49682Moderate

kernel: xtensa: Fix refcount leak bug in time.c

Feb 26, 2025

References

git.kernel.org / stable/c/0dcc1dd8a5dd9240639f1051dfaa2dffc9fbbde5
Patch
git.kernel.org / stable/c/0e403a383c14b63c86bd9df085b7e573e9caee64
Patch
git.kernel.org / stable/c/3e5eb904d9ba657308fc75a5de434b0e58dcb8d7
Patch
git.kernel.org / stable/c/7de4502af68f4f3932f450157f5483eb7b33cb74
Patch
git.kernel.org / stable/c/a0117dc956429f2ede17b323046e1968d1849150
Patch
git.kernel.org / stable/c/af0ff2da01521144bc11194f4c26485d7c9cee73
Patch
git.kernel.org / stable/c/e5234a9d64a976abd134a14710dcd5188158a7c5
Patch
git.kernel.org / stable/c/f1eaf4ba5372ad111f687a80c67e270708e14c23
Patch