CVE-2022-48876 is a kernel NULL pointer dereference vulnerability in the Linux kernel's mac80211 WiFi subsystem. Specifically, it arises from improper initialization of rx->link_sta in certain code paths, leading to crashes when rx->sta is valid but rx->link_sta is not. This affects Linux kernel versions and can be triggered by functions like __ieee80211_rx_h_amsdu. Rated as Medium severity (CVSS 5.5), this vulnerability has a local attack vector (AV:L) with low attack complexity (AC:L) and requires low privileges (PR:L). It can lead to high impact on availability (A:H) due to system crashes, but does not affect confidentiality or integrity. The CWE-476 classification indicates a NULL Pointer Dereference. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1, < 6.1.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.