Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48804

17
FAUCET Score

CVE-2022-48804 is a vulnerability in the Linux kernel's vt_ioctl subsystem, specifically within the vt_setactivate function. It involves a transient integer underflow due to incorrect ordering of array_index_nospec and a decrement operation, leading to an out-of-bounds access. This flaw affects various Linux kernel versions. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (denial of service) without affecting confidentiality or integrity. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available on platforms like Metasploit or ExploitDB. The vulnerability has received no community discussion or media coverage, indicating a low level of public awareness and attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.302CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.267CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.320CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.180CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.101CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
22.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 79th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.22.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.47.1.el9_4
View patch
oraclevendor investigatingvia oracle_oval
Product: cpe:/a:oracle:linux:6:10:UEKR4_ELS
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

redhatCVE-2022-48804Moderate

kernel: vt_ioctl: fix array_index_nospec in vt_setactivate

Jul 16, 2024
oracleoval:com.oracle.ovmsa:def:20240015IMPORTANT

OVMSA-2024-0015: Unbreakable Enterprise kernel security update (IMPORTANT)

References

git.kernel.org / stable/c/170325aba4608bde3e7d21c9c19b7bc266ac0885
Patch
git.kernel.org / stable/c/2a45a6bd1e6d651770aafff57ab3e1d3bb0b42e0
Patch
git.kernel.org / stable/c/61cc70d9e8ef5b042d4ed87994d20100ec8896d9
Patch
git.kernel.org / stable/c/6550bdf52846f85a2a3726a5aa0c7c4399f2fc02
Patch
git.kernel.org / stable/c/778302ca09498b448620edd372dc908bebf80bdf
Patch
git.kernel.org / stable/c/830c5aa302ec16b4ee641aec769462c37f802c90
Patch
git.kernel.org / stable/c/ae3d57411562260ee3f4fd5e875f410002341104
Patch
git.kernel.org / stable/c/ffe54289b02e9c732d6f04c8ebbe3b2d90d32118
Patch