CVE-2022-48804 is a vulnerability in the Linux kernel's vt_ioctl subsystem, specifically within the vt_setactivate function. It involves a transient integer underflow due to incorrect ordering of array_index_nospec and a decrement operation, leading to an out-of-bounds access. This flaw affects various Linux kernel versions. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (denial of service) without affecting confidentiality or integrity. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available on platforms like Metasploit or ExploitDB. The vulnerability has received no community discussion or media coverage, indicating a low level of public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.9.302CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.267CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.320CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.180CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.101CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.