Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48925

22
FAUCET Score

CVE-2022-48925 is a high-severity use-after-free vulnerability in the Linux kernel's RDMA/cma component, specifically affecting the linux_kernel product. The flaw occurs when the resolve_prepare_src() function unconditionally overwrites the src_addr even when the RDMA state is not idle, leading to potential corruption and a use-after-free condition during operations like cma_cancel_operation(). This vulnerability has a CVSS score of 7.8 (High), indicating that a local attacker with low privileges can achieve high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.10, < 5.10.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.26CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 43rd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48925Moderate

kernel: RDMA/cma: Do not change route.addr.src_addr outside state checks

Aug 22, 2024

References

git.kernel.org / stable/c/00265efbd3e5705038c9492a434fda8cf960c8a2
Patch
git.kernel.org / stable/c/22e9f71072fa605cbf033158db58e0790101928d
Patch
git.kernel.org / stable/c/5b1cef5798b4fd6e4fd5522e7b8a26248beeacaa
Patch
git.kernel.org / stable/c/d350724795c7a48b05bf921d94699fbfecf7da0b
Patch