CVE-2022-48820 is a refcount leak vulnerability in the Linux kernel's STM32 USB PHY driver, specifically within the stm32_usbphyc_pll_enable() function. This flaw, affecting Linux kernel versions, could lead to a denial of service or information disclosure. With a CVSS score of 7.1 (High), it requires local access and low privileges, but its complexity is low, making it potentially impactful. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.12, < 5.15.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.16.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.