Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48702

22
FAUCET Score

CVE-2022-48702 is an out-of-bounds access vulnerability in the Linux kernel's ALSA emu10k1 sound driver. Specifically, the snd_emu10k1_pcm_channel_alloc() function can attempt to access memory beyond the allocated array for sound voices when the voice allocator wraps around and a high number of voices are requested. This vulnerability affects Linux kernel versions and can be triggered by local users, for example, by using 'aplay' with 16 channels. Rated with a CVSS score of 7.8 (HIGH), this vulnerability has a local attack vector and low attack complexity, requiring low privileges and no user interaction. Successful exploitation could lead to high confidentiality, integrity, and availability impacts, potentially causing system crashes or arbitrary code execution. There is no evidence of active exploitation, nor are there known public exploit codes (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.328CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.293CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.258CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.213CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.143CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 47th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48702Low

kernel: ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc()

May 3, 2024

References

git.kernel.org / stable/c/39a90720f3abe96625d1224e7a7463410875de4c
Patch
git.kernel.org / stable/c/4204a01ffce97cae1d59edc5848f02be5b2b9178
Patch
git.kernel.org / stable/c/45321a7d02b7cf9b3f97e3987fc1e4d649b82da2
Patch
git.kernel.org / stable/c/45814a53514e10a8014906c882e0d0d38df39cc1
Patch
git.kernel.org / stable/c/637c5310acb48fffcc5657568db3f3e9bc719bfa
Patch
git.kernel.org / stable/c/6b0e260ac3cf289e38446552461caa65e6dab275
Patch
git.kernel.org / stable/c/88aac6684cf8bc885cca15463cb4407e91f28ff7
Patch
git.kernel.org / stable/c/d29f59051d3a07b81281b2df2b8c9dfe4716067f
Patch