Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48901

18
FAUCET Score

CVE-2022-48901 is a vulnerability in the Linux kernel's Btrfs filesystem that can lead to a system crash (denial of service). It occurs when a Btrfs balance operation attempts to relocate data before in-progress snapshot deletions are fully completed, particularly after a system crash. This can result in a WARNING message and system instability. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and primarily impacting availability. There is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.15.27CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
5.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
5.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*
5.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 52nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48901Moderate

kernel: btrfs: do not start relocation until in progress drops are done

Aug 22, 2024

References

git.kernel.org / stable/c/5e70bc827b563caf22e1203428cc3719643de5aa
Patch
git.kernel.org / stable/c/6599d5e8bd758d897fd2ef4dc388ae50278b1f7e
Patch
git.kernel.org / stable/c/b4be6aefa73c9a6899ef3ba9c5faaa8a66e333ef
Patch