CVE-2022-48847 is a vulnerability in the Linux kernel's watch_queue_set_filter function, affecting Linux and Linux kernel products. It stems from an incorrect filter limit check, leading to out-of-bounds writes when processing a too-large filter type. This can result in system crashes, indicated by KASAN slab-out-of-bounds errors. Rated with a CVSS score of 7.8 (High), this vulnerability has a local attack vector with low attack complexity, requiring local privileges. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability. The CWE-787 classification indicates an out-of-bounds write. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.8, < 5.10.106CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.29CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.16.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.