Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48948

25
FAUCET Score

CVE-2022-48948 is a buffer overflow vulnerability in the Linux kernel's USB gadget UVC setup handler, affecting Linux kernel versions. It allows a local, low-privileged attacker to achieve high confidentiality, integrity, and availability impacts with low attack complexity. While no public exploits or Metasploit modules exist, and there's minimal community discussion, the CVSS score of 7.8 (HIGH) indicates significant potential risk. This vulnerability is not currently listed on the KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.35, < 4.9.337CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 55th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48948Moderate

kernel: usb: gadget: uvc: Prevent buffer overflow in setup handler

Oct 21, 2024

References

git.kernel.org / stable/c/06fd17ee92c8f1704c7e54ec0fd50ae0542a49a5
Patch
git.kernel.org / stable/c/4972e3528b968665b596b5434764ff8fd9446d35
Patch
git.kernel.org / stable/c/4c92670b16727365699fe4b19ed32013bab2c107
Patch
git.kernel.org / stable/c/6b41a35b41f77821db24f2d8f66794b390a585c5
Patch
git.kernel.org / stable/c/7b1f773277a72f9756d47a41b94e43506cce1954
Patch
git.kernel.org / stable/c/b8fb1cba934ea122b50f13a4f9d6fc4fdc43d2be
Patch
git.kernel.org / stable/c/bc8380fe5768c564f921f7b4eaba932e330b9e4b
Patch
git.kernel.org / stable/c/c79538f32df12887f110dcd6b9c825b482905f24
Patch
git.kernel.org / stable/c/d1a92bb8d697f170d93fe922da763d7d156b8841
Patch