CVE-2022-48795 is a Linux kernel vulnerability affecting the parisc architecture, specifically a data TLB miss in the sba_unmap_sg function. This bug, caused by an incorrect conditional check during scatter-gather list processing, can lead to a kernel panic due to a null pointer dereference. The vulnerability is rated Medium severity (CVSS 5.5), indicating a local attack vector with low complexity, requiring local privileges. While it doesn't impact confidentiality or integrity, it can lead to high availability impact (system crash). Currently, there is no known active exploitation, publicly available exploit code in Metasploit, Nuclei, or ExploitDB, nor significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.9.303CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.268CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.231CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.181CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.102CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.