Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48636

17
FAUCET Score

CVE-2022-48636 is a NULL pointer dereference vulnerability in the Linux kernel's s390 DASD driver, specifically within the dasd_alias_get_start_dev function. This flaw, affecting Linux kernel versions, can lead to an operating system crash (Oops) due to a race condition where the pavgroup pointer becomes NULL. Rated Medium severity (CVSS 5.5), it requires local access and low privileges to exploit, resulting in a denial of service. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.25, < 4.9.330CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.295CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.260CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.215CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.146CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 60th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48636Moderate

kernel: s390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroup

Apr 28, 2024

References

git.kernel.org / stable/c/2e473351400e3dd66f0b71eddcef82ee45a584c1
Patch
git.kernel.org / stable/c/49f401a98b318761ca2e15d4c7869a20043fbed4
Patch
git.kernel.org / stable/c/650a2e79d176db753654d3dde88e53a2033036ac
Patch
git.kernel.org / stable/c/aaba5ff2742043705bc4c02fd0b2b246e2e16da1
Patch
git.kernel.org / stable/c/d3a67c21b18f33c79382084af556557c442f12a6
Patch
git.kernel.org / stable/c/d86b4267834e6d4af62e3073e48166e349ab1b70
Patch
git.kernel.org / stable/c/db7ba07108a48c0f95b74fabbfd5d63e924f992d
Patch
git.kernel.org / stable/c/f5fcc9d6d71d9ff7fdbdd4b89074e6e24fffc20b
Patch