CVE-2022-48619 is a denial-of-service vulnerability affecting the Linux kernel prior to version 5.17.10, specifically within the drivers/input/input.c component. A local attacker can trigger a system panic by manipulating event codes outside of a bitmap, leading to system unavailability. Rated as Medium severity (CVSS 5.5), this vulnerability requires local access and has a low attack complexity, resulting in high impact to availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.17.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which an event code falls outside of a bitmap.
Jan 9, 2024kernel: event code falling outside of a bitmap in input_set_capability() leads to panic
Mar 21, 2022OVMSA-2024-0003: Unbreakable Enterprise kernel security update (IMPORTANT)