Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48809

17
FAUCET Score

CVE-2022-48809 is a memory leak vulnerability in the Linux kernel's networking subsystem, specifically affecting the handling of skb dst and metadata during uncloning operations. This flaw occurs because an uncloned dst+metadata object is initialized with a refcount of 1, then incorrectly incremented to 2, leading to a persistent reference count that prevents proper memory deallocation. The vulnerability has a CVSS score of 5.5 (MEDIUM), indicating a local attack vector with low complexity, requiring local privileges, and resulting in high availability impact (denial of service due to memory exhaustion). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.3, < 4.9.302CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.267CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.230CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.180CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.101CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 76th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48809Low

kernel: net: fix a memleak when uncloning an skb dst and its metadata

Jul 16, 2024

References

git.kernel.org / stable/c/00e6d6c3bc14dfe32824e2c515f0e0f2d6ecf2f1
Patch
git.kernel.org / stable/c/0be943916d781df2b652793bb2d3ae4f9624c10a
Patch
git.kernel.org / stable/c/4ac84498fbe84a00e7aef185e2bb3e40ce71eca4
Patch
git.kernel.org / stable/c/8b1087b998e273f07be13dcb5f3ca4c309c7f108
Patch
git.kernel.org / stable/c/9eeabdf17fa0ab75381045c867c370f4cc75a613
Patch
git.kernel.org / stable/c/a80817adc2a4c1ba26a7aa5f3ed886e4a18dff88
Patch
git.kernel.org / stable/c/c1ff27d100e2670b03cbfddb9117e5f9fc672540
Patch
git.kernel.org / stable/c/fdcb263fa5cda15b8cb24a641fa2718c47605314
Patch