Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48926

22
FAUCET Score

CVE-2022-48926 is a vulnerability in the Linux kernel's USB gadget RNDIS driver, specifically affecting the handling of the RNDIS response list. The absence of a spinlock for this list creates a race condition, potentially leading to list corruption if multiple list_add operations occur concurrently. This flaw is rated as HIGH severity with a CVSS score of 7.8, indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.6, < 4.9.304CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.269CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.232CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.182CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 42nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48926Moderate

kernel: usb: gadget: rndis: add spinlock for rndis response list

Aug 22, 2024

References

git.kernel.org / stable/c/33222d1571d7ce8c1c75f6b488f38968fa93d2d9
Patch
git.kernel.org / stable/c/4ce247af3f30078d5b97554f1ae6200a0222c15a
Patch
git.kernel.org / stable/c/669c2b178956718407af5631ccbc61c24413f038
Patch
git.kernel.org / stable/c/9ab652d41deab49848673c3dadb57ad338485376
Patch
git.kernel.org / stable/c/9f5d8ba538ef81cd86ea587ca3f8c77e26bea405
Patch
git.kernel.org / stable/c/9f688aadede6b862a0a898792b1a35421c93636f
Patch
git.kernel.org / stable/c/aaaba1c86d04dac8e49bf508b492f81506257da3
Patch
git.kernel.org / stable/c/da514063440b53a27309a4528b726f92c3cfe56f
Patch