Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-2476

16
FAUCET Score

CVE-2022-2476 is a null pointer dereference vulnerability in WavPack 5.4.0, affecting Fedora and WavPack products. It allows for a denial of service (availability impact) due to a crash, triggered by a local attacker with low complexity, requiring user interaction. The vulnerability has a CVSS score of 5.5 (Medium) and is not currently listed on the CISA KEV catalog. There is no public exploit code available, and it has received minimal community discussion or media coverage, indicating low active exploitation or interest.

Impacted Technologies

VendorProductVersion(s)CPE
5.4.0CPE matchmatch criteria
cpe:2.3:a:wavpack:wavpack:5.4.0:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
29.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 37th percentile among its peer group of 5,765 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: 19469-16823Fixed in: 5.6.0-1
microsoftpatch availablevia msrc
Product: cbl2 wavpack 5.6.0-1 on CBL Mariner 2.0Fixed in: 5.6.0-1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: wavpack
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: wavpack

Vendor Advisories (2)

redhatCVE-2022-2476Low

wavpack: null pointer dereference in main() in cli/wvunpack.c

Jul 19, 2022
microsoft2022-Jul/CVE-2022-2476Moderate

A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x561b47a970c6 bp 0x7fff13952fb0 sp 0x7fff1394fca0 T0) ==84257==The signal is caused by a WRITE memory access. ==84257==Hint: address points to the zero page. #0 0x561b47a970c5 in main cli/wvunpack.c:834 #1 0x7efc4f5c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) #2 0x561b47a945ed in _start (/usr/local/bin/wvunpack+0xa5ed) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV cli/wvunpack.c:834 in main ==84257==ABORTING

Jul 12, 2022

References

github.com / dbry/WavPack/issues/121
ExploitIssue TrackingThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CK45CC7MQ54SHEIJ63PW3HP4BCPTX6QP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QMIXZWB3OURGBAEU3T5HQY56BN2ZVLYF