CVE-2022-48815 is a medium-severity vulnerability in the Linux kernel's net: dsa: bcm_sf2 driver. It arises from an incorrect use of devres for MDIO bus management, leading to a potential kernel panic during device shutdown if the MDIO bus was not properly unregistered. This issue affects Linux kernel versions where the bcm_sf2 driver is present. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity and low privileges required, resulting in high availability impact (denial of service). There is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.9, < 5.10.101CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.16.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.