Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48837

22
FAUCET Score

CVE-2022-48837 is a high-severity integer overflow vulnerability in the Linux kernel's USB gadget RNDIS driver, specifically within the rndis_set_response() function. A large "BufOffset" value can cause an integer overflow during the "BufOffset + 8" operation, potentially leading to a local privilege escalation with high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.9.302, < 4.9.308CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.14.267, < 4.14.273CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.19.230, < 4.19.236CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.180, < 5.4.187CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.101, < 5.10.108CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 52nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48837Moderate

kernel: usb: gadget: rndis: prevent integer overflow in rndis_set_response()

Jul 16, 2024

References

git.kernel.org / stable/c/138d4f739b35dfb40438a0d5d7054965763bfbe7
Mailing ListPatch
git.kernel.org / stable/c/21829376268397f9fd2c35cfa9135937b6aa3a1e
Mailing ListPatch
git.kernel.org / stable/c/28bc0267399f42f987916a7174e2e32f0833cc65
Mailing ListPatch
git.kernel.org / stable/c/56b38e3ca4064041d93c1ca18828c8cedad2e16c
Mailing ListPatch
git.kernel.org / stable/c/65f3324f4b6fed78b8761c3b74615ecf0ffa81fa
Mailing ListPatch
git.kernel.org / stable/c/8b3e4d26bc9cd0f6373d0095b9ffd99e7da8006b
Mailing ListPatch
git.kernel.org / stable/c/c7953cf03a26876d676145ce5d2ae6d8c9630b90
Mailing ListPatch
git.kernel.org / stable/c/df7e088d51cdf78b1a0bf1f3d405c2593295c7b0
Mailing ListPatch