Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48966

18
FAUCET Score

CVE-2022-48966 is an out-of-bounds read vulnerability in the Linux kernel's mvneta network driver, specifically affecting the mvneta_config_rss() function. This flaw occurs because user-supplied input for pp->indir[0] is not properly bounds-checked before being used in a CPU bitmap, potentially leading to an out-of-bounds read. With a CVSS score of 7.1 (High), this vulnerability can be exploited locally with low attack complexity and requires low privileges, potentially resulting in high confidentiality impact and high availability impact. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-125, indicating an out-of-bounds read. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.5, < 4.9.336CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.302CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.269CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.227CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.159CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 49th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-48966Moderate

kernel: net: mvneta: Prevent out of bounds read in mvneta_config_rss()

Oct 21, 2024

References

git.kernel.org / stable/c/146ebee8fcdb349d7ec0e49915e6cdafb92544ae
Patch
git.kernel.org / stable/c/3ceffb8f410b93553fb16fe7e84aa0d35b3ba79b
Patch
git.kernel.org / stable/c/47a1a2f6cd5ec3a4f8a2d9bfa1e0605347cdb92c
Patch
git.kernel.org / stable/c/5a142486a0db6b0b85031f22d69acd0cdcf8f72b
Patch
git.kernel.org / stable/c/6ca0a506dddc3e1d636935eef339576b263bf3d8
Patch
git.kernel.org / stable/c/a6b30598fec84f8809f5417cde73071ca43e8471
Patch
git.kernel.org / stable/c/e8b4fc13900b8e8be48debffd0dfd391772501f7
Patch
git.kernel.org / stable/c/eec1fc21edc2bb99c9e66cf66f0b5d4d643fbb50
Patch