Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49700

21
FAUCET Score

CVE-2022-49700 is a high-severity vulnerability in the Linux kernel's SLUB memory allocator. It arises from missing Transaction ID (TID) updates during slab deactivation, which can lead to race conditions. This flaw could result in memory corruption, including lost objects or, in rare cases, a use-after-free condition where a page is freed while still containing slab objects. The vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low attack complexity, requiring low privileges, and no user interaction. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability. It is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.1, < 4.9.323CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.288CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.252CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.205CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.130CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 58th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.11.1.el9_2
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49700Moderate

kernel: mm/slub: add missing TID updates on slab deactivation

Feb 26, 2025

References

git.kernel.org / stable/c/0515cc9b6b24877f59b222ade704bfaa42caa2a6
Patch
git.kernel.org / stable/c/197e257da473c725dfe47759c3ee02f2398d8ea5
Patch
git.kernel.org / stable/c/308c6d0e1f200fd26c71270c6e6bfcf0fc6ff082
Patch
git.kernel.org / stable/c/6c32496964da0dc230cea763a0e934b2e02dabd5
Patch
git.kernel.org / stable/c/d6a597450e686d4c6388bd3cdcb17224b4dae7f0
Patch
git.kernel.org / stable/c/e2b2f0e2e34d71ae6c2a1114fd3c525930e84bc7
Patch
git.kernel.org / stable/c/e7e3e90d671078455a3a08189f89d85b3da2de9e
Patch
git.kernel.org / stable/c/eeaa345e128515135ccb864c04482180c08e3259
Patch