Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49865

19
FAUCET Score

CVE-2022-49865 is a kernel-network information leak vulnerability affecting the Linux kernel's IPv6 address label functionality. Specifically, an uninitialized field within the 'struct ifaddrlblmsg' when sent over the network could expose 1 byte of sensitive data. This vulnerability carries a CVSS score of 7.1 (HIGH), indicating that a local attacker with low privileges could exploit it with low attack complexity, potentially leading to high confidentiality impact. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.25, < 4.9.334CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.300CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.267CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.225CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.155CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 36th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-49865Moderate

kernel: ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network

May 1, 2025

References

git.kernel.org / stable/c/0f85b7ae7c4b5d7b4bbf7ac653a733c181a8a2bf
Patch
git.kernel.org / stable/c/2acb2779b147decd300c117683d5a32ce61c75d6
Patch
git.kernel.org / stable/c/49e92ba5ecd7d72ba369dde2ccff738edd028a47
Patch
git.kernel.org / stable/c/568a47ff756f913e8b374c2af9d22cd2c772c744
Patch
git.kernel.org / stable/c/58cd7fdc8c1e6c7873acc08f190069fed88d1c12
Patch
git.kernel.org / stable/c/6d26d0587abccb9835382a0b53faa7b9b1cd83e3
Patch
git.kernel.org / stable/c/a033b86c7f7621fde31f0364af8986f43b44914f
Patch
git.kernel.org / stable/c/c23fb2c82267638f9d206cb96bb93e1f93ad7828
Patch