Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49840

21
FAUCET Score

CVE-2022-49840 is a use-after-free vulnerability in the Linux kernel's BPF subsystem, specifically affecting the bpf_prog_test_run_skb function. This flaw occurs on aarch64 architectures when the size of a user BPF program leads to unaligned access to the skb_shared_info structure, potentially triggered when KFENCE is enabled. With a CVSS score of 7.8 (High), successful exploitation could lead to high confidentiality, integrity, and availability impacts, requiring local access and low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.12, < 4.14.300CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.267CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.225CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.156CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.80CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 36th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49840Moderate

kernel: bpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()

May 1, 2025

References

git.kernel.org / stable/c/047824a730699c6c66df43306b80f700c9dfc2fd
Patch
git.kernel.org / stable/c/1b597f2d6a55e9f549989913860ad5170da04964
Patch
git.kernel.org / stable/c/730fb1ef974a13915bc7651364d8b3318891cd70
Patch
git.kernel.org / stable/c/7a704dbfd3735304e261f2787c52fbc7c3884736
Patch
git.kernel.org / stable/c/d3fd203f36d46aa29600a72d57a1b61af80e4a25
Patch
git.kernel.org / stable/c/e60f37a1d379c821c17b08f366412dce9ef3d99f
Patch
git.kernel.org / stable/c/eaa8edd86514afac9deb9bf9a5053e74f37edf40
Patch