Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-320263
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 07:39
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T07:39:45.514153+00:00",
"id": "EUVD-2026-320263"
}
CVE-2022-48804 (GCVE-0-2022-48804)
Vulnerability from cvelistv5 – Published: 2024-07-16 11:43 – Updated: 2026-05-23 15:20
VLAI
EPSS
VEX
Title
vt_ioctl: fix array_index_nospec in vt_setactivate
Summary
In the Linux kernel, the following vulnerability has been resolved:
vt_ioctl: fix array_index_nospec in vt_setactivate
array_index_nospec ensures that an out-of-bounds value is set to zero
on the transient path. Decreasing the value by one afterwards causes
a transient integer underflow. vsa.console should be decreased first
and then sanitized with array_index_nospec.
Kasper Acknowledgements: Jakob Koschel, Brian Johannesmeyer, Kaveh
Razavi, Herbert Bos, Cristiano Giuffrida from the VUSec group at VU
Amsterdam.
Severity
No CVSS data available.
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-09-10 16:58 UTC
Assigner
References
8 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
0ec459ec174031fad02a55e622cf2fc0d2e75a25 , < 830c5aa302ec16b4ee641aec769462c37f802c90
(git)
Affected: 4334a6ae867aa12f01c1755368fd0de4c926ac75 , < 2a45a6bd1e6d651770aafff57ab3e1d3bb0b42e0 (git) Affected: e97267cb4d1ee01ca0929638ec0fcbb0904f903d , < 170325aba4608bde3e7d21c9c19b7bc266ac0885 (git) Affected: e97267cb4d1ee01ca0929638ec0fcbb0904f903d , < ae3d57411562260ee3f4fd5e875f410002341104 (git) Affected: e97267cb4d1ee01ca0929638ec0fcbb0904f903d , < 778302ca09498b448620edd372dc908bebf80bdf (git) Affected: e97267cb4d1ee01ca0929638ec0fcbb0904f903d , < ffe54289b02e9c732d6f04c8ebbe3b2d90d32118 (git) Affected: e97267cb4d1ee01ca0929638ec0fcbb0904f903d , < 6550bdf52846f85a2a3726a5aa0c7c4399f2fc02 (git) Affected: e97267cb4d1ee01ca0929638ec0fcbb0904f903d , < 61cc70d9e8ef5b042d4ed87994d20100ec8896d9 (git) Affected: 458697ab18b512445ac273ce68a9f8fd623fc0a3 (git) Affected: 1aa698b65186c13ed775896ed1dfec7c26c73d60 (git) Affected: 52ef74c21c277e50de771fc722d814a830b3036b (git) Affected: 4.9.130 , < 4.9.302 (semver) Affected: 4.14.73 , < 4.14.267 (semver) Affected: 3.16.62 , < 3.17 (semver) Affected: 4.4.159 , < 4.5 (semver) Affected: 4.18.11 , < 4.19 (semver) |
|
| Linux | Linux |
Affected:
4.19
Unaffected: 0 , < 4.19 (semver) Unaffected: 4.9.302 , ≤ 4.9.* (semver) Unaffected: 4.14.267 , ≤ 4.14.* (semver) Unaffected: 4.19.230 , ≤ 4.19.* (semver) Unaffected: 5.4.180 , ≤ 5.4.* (semver) Unaffected: 5.10.101 , ≤ 5.10.* (semver) Unaffected: 5.15.24 , ≤ 5.15.* (semver) Unaffected: 5.16.10 , ≤ 5.16.* (semver) Unaffected: 5.17 , ≤ * (original_commit_for_fix) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-03T15:25:01.606Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/830c5aa302ec16b4ee641aec769462c37f802c90"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/2a45a6bd1e6d651770aafff57ab3e1d3bb0b42e0"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/170325aba4608bde3e7d21c9c19b7bc266ac0885"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/ae3d57411562260ee3f4fd5e875f410002341104"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/778302ca09498b448620edd372dc908bebf80bdf"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/ffe54289b02e9c732d6f04c8ebbe3b2d90d32118"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/6550bdf52846f85a2a3726a5aa0c7c4399f2fc02"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/61cc70d9e8ef5b042d4ed87994d20100ec8896d9"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2022-48804",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-10T16:58:54.114050Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-11T17:34:14.042Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/tty/vt/vt_ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "830c5aa302ec16b4ee641aec769462c37f802c90",
"status": "affected",
"version": "0ec459ec174031fad02a55e622cf2fc0d2e75a25",
"versionType": "git"
},
{
"lessThan": "2a45a6bd1e6d651770aafff57ab3e1d3bb0b42e0",
"status": "affected",
"version": "4334a6ae867aa12f01c1755368fd0de4c926ac75",
"versionType": "git"
},
{
"lessThan": "170325aba4608bde3e7d21c9c19b7bc266ac0885",
"status": "affected",
"version": "e97267cb4d1ee01ca0929638ec0fcbb0904f903d",
"versionType": "git"
},
{
"lessThan": "ae3d57411562260ee3f4fd5e875f410002341104",
"status": "affected",
"version": "e97267cb4d1ee01ca0929638ec0fcbb0904f903d",
"versionType": "git"
},
{
"lessThan": "778302ca09498b448620edd372dc908bebf80bdf",
"status": "affected",
"version": "e97267cb4d1ee01ca0929638ec0fcbb0904f903d",
"versionType": "git"
},
{
"lessThan": "ffe54289b02e9c732d6f04c8ebbe3b2d90d32118",
"status": "affected",
"version": "e97267cb4d1ee01ca0929638ec0fcbb0904f903d",
"versionType": "git"
},
{
"lessThan": "6550bdf52846f85a2a3726a5aa0c7c4399f2fc02",
"status": "affected",
"version": "e97267cb4d1ee01ca0929638ec0fcbb0904f903d",
"versionType": "git"
},
{
"lessThan": "61cc70d9e8ef5b042d4ed87994d20100ec8896d9",
"status": "affected",
"version": "e97267cb4d1ee01ca0929638ec0fcbb0904f903d",
"versionType": "git"
},
{
"status": "affected",
"version": "458697ab18b512445ac273ce68a9f8fd623fc0a3",
"versionType": "git"
},
{
"status": "affected",
"version": "1aa698b65186c13ed775896ed1dfec7c26c73d60",
"versionType": "git"
},
{
"status": "affected",
"version": "52ef74c21c277e50de771fc722d814a830b3036b",
"versionType": "git"
},
{
"lessThan": "4.9.302",
"status": "affected",
"version": "4.9.130",
"versionType": "semver"
},
{
"lessThan": "4.14.267",
"status": "affected",
"version": "4.14.73",
"versionType": "semver"
},
{
"lessThan": "3.17",
"status": "affected",
"version": "3.16.62",
"versionType": "semver"
},
{
"lessThan": "4.5",
"status": "affected",
"version": "4.4.159",
"versionType": "semver"
},
{
"lessThan": "4.19",
"status": "affected",
"version": "4.18.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/tty/vt/vt_ioctl.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"lessThan": "4.19",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.9.*",
"status": "unaffected",
"version": "4.9.302",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.14.*",
"status": "unaffected",
"version": "4.14.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.19.*",
"status": "unaffected",
"version": "4.19.230",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.180",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.24",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.16.*",
"status": "unaffected",
"version": "5.16.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "5.17",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.9.302",
"versionStartIncluding": "4.9.130",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.14.267",
"versionStartIncluding": "4.14.73",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.19.230",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.180",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.101",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.24",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.16.10",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.17",
"versionStartIncluding": "4.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.16.62",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.4.159",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.18.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt_ioctl: fix array_index_nospec in vt_setactivate\n\narray_index_nospec ensures that an out-of-bounds value is set to zero\non the transient path. Decreasing the value by one afterwards causes\na transient integer underflow. vsa.console should be decreased first\nand then sanitized with array_index_nospec.\n\nKasper Acknowledgements: Jakob Koschel, Brian Johannesmeyer, Kaveh\nRazavi, Herbert Bos, Cristiano Giuffrida from the VUSec group at VU\nAmsterdam."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-23T15:20:45.845Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/830c5aa302ec16b4ee641aec769462c37f802c90"
},
{
"url": "https://git.kernel.org/stable/c/2a45a6bd1e6d651770aafff57ab3e1d3bb0b42e0"
},
{
"url": "https://git.kernel.org/stable/c/170325aba4608bde3e7d21c9c19b7bc266ac0885"
},
{
"url": "https://git.kernel.org/stable/c/ae3d57411562260ee3f4fd5e875f410002341104"
},
{
"url": "https://git.kernel.org/stable/c/778302ca09498b448620edd372dc908bebf80bdf"
},
{
"url": "https://git.kernel.org/stable/c/ffe54289b02e9c732d6f04c8ebbe3b2d90d32118"
},
{
"url": "https://git.kernel.org/stable/c/6550bdf52846f85a2a3726a5aa0c7c4399f2fc02"
},
{
"url": "https://git.kernel.org/stable/c/61cc70d9e8ef5b042d4ed87994d20100ec8896d9"
}
],
"title": "vt_ioctl: fix array_index_nospec in vt_setactivate",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2022-48804",
"datePublished": "2024-07-16T11:43:56.278Z",
"dateReserved": "2024-07-16T11:38:08.896Z",
"dateUpdated": "2026-05-23T15:20:45.845Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…