Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48956

21
FAUCET Score

CVE-2022-48956 is a use-after-free vulnerability in the Linux kernel's IPv6 fragmentation (ip6_fragment) function, specifically affecting the UDP stack. This flaw occurs because the rcu_read_lock() is not consistently held by callers, leading to memory corruption. It impacts Linux kernel versions and has a CVSS score of 7.8 (HIGH), indicating a local attack vector with low complexity, potentially leading to high confidentiality, integrity, and availability impacts. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.13, < 4.14.302CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.269CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.227CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.159CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.83CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 54th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48956Moderate

kernel: ipv6: avoid use-after-free in ip6_fragment()

Oct 21, 2024

References

git.kernel.org / stable/c/6b6d3be3661bff2746cab26147bd629aa034e094
Patch
git.kernel.org / stable/c/7390c70bd431cbfa6951477e2c80a301643e284b
Patch
git.kernel.org / stable/c/7e0dcd5f3ade221a6126278aca60c8ab4cc3bce9
Patch
git.kernel.org / stable/c/803e84867de59a1e5d126666d25eb4860cfd2ebe
Patch
git.kernel.org / stable/c/8208d7e56b1e579320b9ff3712739ad2e63e1f86
Patch
git.kernel.org / stable/c/9b1a468a455d8319041528778d0e684a4c062792
Patch
git.kernel.org / stable/c/b3d7ff8c04a83279fb7641fc4d5aa82a602df7c0
Patch