Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48855

19
FAUCET Score

CVE-2022-48855 is a kernel information leak vulnerability affecting the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. Specifically, an uninitialized field (r->idiag_expires) in SCTP socket diagnostic messages could expose 4 bytes of kernel memory. This vulnerability has a CVSS score of 7.1 (High), indicating that a local attacker with low privileges could exploit it to gain sensitive information, potentially leading to further compromise. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.7, < 4.9.307CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.272CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.235CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.185CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.106CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 45th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48855Moderate

kernel: sctp: fix kernel-infoleak for SCTP sockets

Jul 16, 2024

References

git.kernel.org / stable/c/1502f15b9f29c41883a6139f2923523873282a83
Patch
git.kernel.org / stable/c/2d8fa3fdf4542a2174a72d92018f488d65d848c5
Patch
git.kernel.org / stable/c/3fc0fd724d199e061432b66a8d85b7d48fe485f7
Patch
git.kernel.org / stable/c/41a2864cf719c17294f417726edd411643462ab8
Patch
git.kernel.org / stable/c/633593a808980f82d251d0ca89730d8bb8b0220c
Patch
git.kernel.org / stable/c/b7e4d9ba2ddb78801488b4c623875b81fb46b545
Patch
git.kernel.org / stable/c/bbf59d7ae558940cfa2b36a287fd1e88d83f89f8
Patch
git.kernel.org / stable/c/d828b0fe6631f3ae8709ac9a10c77c5836c76a08
Patch