CVE-2022-48716 is a critical vulnerability in the Linux kernel's audio subsystem (ASoC: codecs: wcd938x) that stems from an incorrect use of port IDs, potentially leading to out-of-bounds array access and memory corruption. This flaw carries a CVSS score of 9.8 (Critical), indicating it can be exploited remotely without user interaction to achieve full confidentiality, integrity, and availability compromise. There is currently no public exploit intelligence, such as Metasploit modules or ExploitDB entries, and it has not been added to the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.14, < 5.15.22CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.16.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.