Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48629

16
FAUCET Score

CVE-2022-48629 addresses a vulnerability in the Linux kernel's qcom-rng crypto driver, specifically affecting the generation of random numbers. The issue arises because the qcom_rng_read() function could return partially filled buffers, leading to sections of zeros in the generated randomness, thereby compromising its quality. This flaw impacts products utilizing the Linux kernel, such as the msm8974 SoC found in devices like the Nexus 5. The vulnerability is rated Medium severity (CVSS 5.5) with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. This indicates that a local attacker with low privileges can exploit it with low attack complexity, potentially leading to a high impact on availability by degrading the quality of cryptographic randomness. There is no direct impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or concern regarding its exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19, < 4.19.236CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.187CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.108CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.31CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 86th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48629Low

kernel: crypto: qcom-rng - ensure buffer for generate is completely filled

Mar 5, 2024

References

git.kernel.org / stable/c/0f9b7b8df17525e464294c916acc8194ce38446b
ExploitMailing ListPatch
git.kernel.org / stable/c/184f7bd08ce56f003530fc19f160d54e75bf5c9d
ExploitMailing ListPatch
git.kernel.org / stable/c/485995cbc98a4f77cfd4f8ed4dd7ff8ab262964d
ExploitMailing ListPatch
git.kernel.org / stable/c/a680b1832ced3b5fa7c93484248fd221ea0d614b
ExploitMailing ListPatch
git.kernel.org / stable/c/a8e32bbb96c25b7ab29b1894dcd45e0b3b08fd9d
ExploitMailing ListPatch
git.kernel.org / stable/c/ab9337c7cb6f875b6286440b1adfbeeef2b2b2bd
ExploitMailing ListPatch