Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49999

21
FAUCET Score

CVE-2022-49999 describes a race condition in the Linux kernel's Btrfs filesystem, specifically affecting the space cache mechanism. This flaw can lead to corruption of the free space cache, resulting in errors like "unable to add free space," missing free space information, or double-accounted space. The vulnerability impacts Linux kernel versions utilizing Btrfs. The vulnerability is rated HIGH with a CVSS score of 7.8. It involves a local attack vector (AV:L) with low attack complexity (AC:L) and requires low privileges (PR:L). Successful exploitation can lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H) due to potential filesystem corruption and data loss. There is currently no evidence of active exploitation for CVE-2022-49999. No public exploit code or Metasploit modules are available, and there is no significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.12, < 5.15.65CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.19.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 40th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49999

kernel: btrfs: fix space cache corruption and potential double allocations

Jun 18, 2025

References

git.kernel.org / stable/c/92dc4c1a8e58bcc7a183a4c86b055c24cc88d967
Patch
git.kernel.org / stable/c/a2e54eb64229f07f917b05d0c323604fda9b89f7
Patch
git.kernel.org / stable/c/ced8ecf026fd8084cf175530ff85c76d6085d715
Patch