Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49945

19
FAUCET Score

CVE-2022-49945 is an array out-of-bounds vulnerability in the Linux kernel's gpio-fan driver. This flaw allows a local attacker to trigger a kernel oops by manipulating the thermal cooling device state, leading to a denial of service. While rated High severity (CVSS 7.1), there is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.1, < 4.9.328CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.293CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.258CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.213CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.142CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
9.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 35th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49945

kernel: hwmon: (gpio-fan) Fix array out of bounds access

Jun 18, 2025

References

git.kernel.org / stable/c/3263984c7acdcb0658155b05a724ed45a10de76d
Patch
git.kernel.org / stable/c/3ff866455e1e263a9ac1958095fd440984248e2f
Patch
git.kernel.org / stable/c/517dba798793e69b510779c3cde7224a65f3ed1d
Patch
git.kernel.org / stable/c/53196e0376205ed49b75bfd0475af5e0fbd20156
Patch
git.kernel.org / stable/c/7756eb1ed124753f4d64f761fc3d84290dffcb4d
Patch
git.kernel.org / stable/c/c8ae6a18708f260ccdeef6ba53af7548457dc26c
Patch
git.kernel.org / stable/c/e9f6972ab40a82bd7f6d36800792ba2e084474d8
Patch
git.kernel.org / stable/c/f233d2be38dbbb22299192292983037f01ab363c
Patch