CVE-2022-48703 is a NULL pointer dereference vulnerability in the Linux kernel's int340x_thermal driver, affecting Linux kernel versions. It occurs when the GDDV returns a zero-length buffer, causing kmemdup() to return ZERO_SIZE_PTR (0x10), which is then dereferenced. Rated as Medium severity (CVSS 5.5), this local attack (AV:L) requires low privileges (PR:L) and can lead to high availability impact (A:H), potentially causing system crashes. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.19.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
May 14, 2024kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
May 3, 2024