Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48731

17
FAUCET Score

CVE-2022-48731 is a vulnerability in the Linux kernel's kmemleak memory leak detector, specifically affecting systems utilizing AMD APUs. It arises when devm_request_free_mem_region() and devm_memremap_pages() create a very large memory "hole," causing the kmemleak scanner to enter an inefficient, prolonged loop. This can lead to a soft lockup, rendering the system unresponsive. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges. The primary impact is high availability loss (A:H) due to the system lockup, with no impact on confidentiality or integrity. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.4.178CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.99CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.22CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.8CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
5.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 36th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48731Low

kernel: mm/kmemleak: avoid scanning potential huge holes

Jun 20, 2024

References

git.kernel.org / stable/c/352715593e81b917ce1b321e794549815b850134
Patch
git.kernel.org / stable/c/a5389c80992f0001ee505838fe6a8b20897ce96e
Patch
git.kernel.org / stable/c/c10a0f877fe007021d70f9cada240f42adc2b5db
Patch
git.kernel.org / stable/c/cebb0aceb21ad91429617a40e3a17444fabf1529
Patch
git.kernel.org / stable/c/d3533ee20e9a0e2e8f60384da7450d43d1c63d1a
Patch