Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48947

21
FAUCET Score

CVE-2022-48947 is a vulnerability in the Linux kernel's Bluetooth L2CAP implementation, affecting Linux kernel versions. It stems from an integer overflow (CWE-190) where repeated L2CAP_CONF_REQ packets can cause the chan->num_conf_rsp counter to wrap around, leading to a denial-of-service condition. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a local attack vector and low attack complexity, requiring local privileges to exploit. The primary impact is high availability loss, with no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
15.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 68th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.13.1.el9_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48947Moderate

kernel: Bluetooth: L2CAP: Fix u8 overflow

Oct 21, 2024

References

git.kernel.org / stable/c/19a78143961a197de8502f4f29c453b913dc3c29
Patch
git.kernel.org / stable/c/49d5867819ab7c744852b45509e8469839c07e0e
Patch
git.kernel.org / stable/c/5550bbf709c323194881737fd290c4bada9e6ead
Patch
git.kernel.org / stable/c/95f1847a361c7b4bf7d74c06ecb6968455082c1a
Patch
git.kernel.org / stable/c/9fdc79b571434af7bc742da40a3405f038b637a7
Patch
git.kernel.org / stable/c/ad528fde0702903208d0a79d88d5a42ae3fc235b
Patch
git.kernel.org / stable/c/bcd70260ef56e0aee8a4fc6cd214a419900b0765
Patch
git.kernel.org / stable/c/f3fe6817156a2ad4b06f01afab04638a34d7c9a6
Patch