cbcvebase.
CVE-2022-1048
published 2022-04-29

CVE-2022-1048: A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.16.18-1 (bookworm)linux 5.16.18-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 5.16.18-15.16.18-1
linuxlinux_kernel>= 0 < 4.15.0-191.2024.15.0-191.202
linuxlinux_kernel>= 0 < 5.4.0-124.1405.4.0-124.140
linuxlinux_kernel>= 0 < 5.15.0-37.395.15.0-37.39
linuxlinux_kernel>= 2.6.12 < 4.14.2794.14.279
linuxlinux_kernel>= 4.15 < 4.19.2434.19.243
linuxlinux_kernel>= 4.20 < 5.4.1935.4.193
linuxlinux_kernel>= 5.11 < 5.15.325.15.32
linuxlinux_kernel>= 5.16 < 5.16.185.16.18
linuxlinux_kernel>= 5.5 < 5.10.1095.10.109
msrccbl2_kernel_5.15.37.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.116.1-1_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
cisa7.8HIGH