Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48937

13
FAUCET Score

CVE-2022-48937 addresses a soft lockup vulnerability in the Linux kernel's io_uring subsystem. Specifically, the io_add_buffers() function, when looping approximately 65535 times and performing kmalloc() calls, can cause a CPU to become stuck, particularly when kernel debugging features like KASAN are enabled. This issue affects Linux kernel versions. The vulnerability is rated as LOW severity (CVSS 3.1: 3.3/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). It requires local access and low privileges to trigger, with a low attack complexity. The primary impact is a denial of service (soft lockup) due to system unresponsiveness, without affecting confidentiality or integrity. There is no evidence of active exploitation for CVE-2022-48937. No public exploit code or Metasploit/Nuclei modules are available, and there is minimal community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.7, < 5.10.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.26CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 37th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48937Moderate

kernel: io_uring: add a schedule point in io_add_buffers()

Aug 22, 2024

References

git.kernel.org / stable/c/4a93c6594613c3429b6f30136fff115c7f803af4
Patch
git.kernel.org / stable/c/8f3cc3c5bc43d03b5748ac4fb8d180084952c36a
Patch
git.kernel.org / stable/c/c718ea4e7382e18957ed0e88a5f855e2122d9c00
Patch
git.kernel.org / stable/c/f240762f88b4b1b58561939ffd44837759756477
Patch