CVE-2022-48652 is a vulnerability in the Linux kernel's ice network driver, specifically affecting the handling of Traffic Classes (TCs) and allocated queues. When the number of TCs is updated to be greater than the allocated queues, the driver can enter an inconsistent state, leading to an invalid pointer access and a kernel crash. This issue primarily impacts systems utilizing the ice network driver. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity. A successful exploit could lead to a denial-of-service (DoS) condition by crashing the kernel, but it does not appear to directly impact confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.18.8, < 5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.19.1, < 5.19.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:-:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:rc4:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:rc5:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.