Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-48972

17
FAUCET Score

CVE-2022-48972 is a NULL pointer dereference vulnerability in the Linux kernel's mac802154 module, specifically within the ieee802154_if_add() function. This flaw occurs because a list within the wpan_dev structure, allocated as private data for a netdev, is not properly initialized, leading to a system crash when the cfg802154_netdev_notifier_call() attempts to manage it. Rated Medium with a CVSS score of 5.5, it requires local access and low privileges to achieve a denial-of-service (system crash). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.19, < 4.9.336CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.302CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.269CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.227CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.159CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 76th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2022-48972Moderate

kernel: mac802154: fix missing INIT_LIST_HEAD in ieee802154_if_add()

Oct 21, 2024

References

git.kernel.org / stable/c/1831d4540406708e48239cf38fd9c3b7ea98e08f
Patch
git.kernel.org / stable/c/42c319635c0cf7eb36eccac6cda76532f47b61a3
Patch
git.kernel.org / stable/c/623918f40fa68e3bb21312a3fafb90f491bf5358
Patch
git.kernel.org / stable/c/7410f4d1221bb182510b7778ab6eefa8b9b7102d
Patch
git.kernel.org / stable/c/9980a3ea20de40c83817877106c909cb032692d2
Patch
git.kernel.org / stable/c/a110287ef4a423980309490df632e1c1e73b3dc9
Patch
git.kernel.org / stable/c/b3d72d3135d2ef68296c1ee174436efd65386f04
Patch
git.kernel.org / stable/c/f00c84fb1635c27ba24ec5df65d5bd7d7dc00008
Patch