Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48876

17
FAUCET Score

CVE-2022-48876 is a kernel NULL pointer dereference vulnerability in the Linux kernel's mac80211 WiFi subsystem. Specifically, it arises from improper initialization of rx->link_sta in certain code paths, leading to crashes when rx->sta is valid but rx->link_sta is not. This affects Linux kernel versions and can be triggered by functions like __ieee80211_rx_h_amsdu. Rated as Medium severity (CVSS 5.5), this vulnerability has a local attack vector (AV:L) with low attack complexity (AC:L) and requires low privileges (PR:L). It can lead to high impact on availability (A:H) due to system crashes, but does not affect confidentiality or integrity. The CWE-476 classification indicates a NULL Pointer Dereference. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting low public awareness and attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.1, < 6.1.8CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 51st percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48876Moderate

kernel: wifi: mac80211: fix initialization of rx-&gt;link and rx-&gt;link_sta

Aug 21, 2024

References

git.kernel.org / stable/c/a57c981d9f24d2bd89eaa76dc477e8ca252e22e8
Patch
git.kernel.org / stable/c/e66b7920aa5ac5b1a1997a454004ba9246a3c005
Patch