Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48946

19
FAUCET Score

CVE-2022-48946 is a medium-severity vulnerability in the Linux kernel's UDF filesystem, specifically affecting how preallocation extents are handled. A flaw in the code could lead to corruption of the extent tree header when a preallocation extent is the first in an extent block, resulting in a denial of service. With a CVSS score of 5.5, this vulnerability requires local access and low privileges, but does not involve user interaction. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 70th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48946Moderate

kernel: udf: Fix preallocation discarding at indirect extent boundary

Oct 21, 2024

References

git.kernel.org / stable/c/12a88f572d6d94b5c0b72e2d1782cc2e96ac06cf
Patch
git.kernel.org / stable/c/1a075f4a549481ce6e8518d8379f193ccec6b746
Patch
git.kernel.org / stable/c/4d835efd561dfb9bf5409f11f4ecd428d5d29226
Patch
git.kernel.org / stable/c/63dbbd8f1499b0a161e701a04aa50148d60bd1f7
Patch
git.kernel.org / stable/c/72f651c96c8aadf087fd782d551bf7db648a8c2e
Patch
git.kernel.org / stable/c/7665857f88557c372da35534165721156756f77f
Patch
git.kernel.org / stable/c/ae56d9a017724f130cf1a263dd82a78d2a6e3852
Patch
git.kernel.org / stable/c/c8b6fa4511a7900db9fb0353b630d4d2ed1ba99c
Patch
git.kernel.org / stable/c/cfe4c1b25dd6d2f056afc00b7c98bcb3dd0b1fc3
Patch