cbcvebase.
CVE-2022-48701
published 2024-05-03

CVE-2022-48701: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() There may be…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() There may be a bad USB audio device with a USB ID of (0x04fa, 0x4201) and the number of it's interfaces less than 4, an out-of-bounds read bug occurs when parsing the interface descriptor for this device. Fix this by checking the number of interfaces.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.19.11-1 (bookworm)linux 5.19.11-1 (bookworm)
linuxlinux
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < b970518014f2f0f6c493fb86c1e092b936899061b970518014f2f0f6c493fb86c1e092b936899061
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < 91904870370fd986c29719846ed76d559de4325191904870370fd986c29719846ed76d559de43251
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < 2a308e415d247a23d4d64c964c02e782eede29362a308e415d247a23d4d64c964c02e782eede2936
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < 0492798bf8dfcc09c9337a1ba065da1d1ca687120492798bf8dfcc09c9337a1ba065da1d1ca68712
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < 6123bec8480d23369e2ee0b2208611619f269faf6123bec8480d23369e2ee0b2208611619f269faf
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < 98e8e67395cc6d0cdf3a771f86ea42d0ee6e59dd98e8e67395cc6d0cdf3a771f86ea42d0ee6e59dd
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < 8293e61bbf908b18ff9935238d4fc2ad359e3fe08293e61bbf908b18ff9935238d4fc2ad359e3fe0
linuxlinux>= b9d43bcd061956c8144bcb453d07d13236b6ab28 < e53f47f6c1a56d2af728909f1cb894da6b43d9bfe53f47f6c1a56d2af728909f1cb894da6b43d9bf
linuxlinux_kernel< 4.9.3284.9.328
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.148-15.10.148-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 4.10 < 4.14.2934.14.293
linuxlinux_kernel>= 4.15 < 4.19.2584.19.258
linuxlinux_kernel>= 4.20 < 5.4.2135.4.213
linuxlinux_kernel>= 5.11 < 5.15.685.15.68
linuxlinux_kernel>= 5.16 < 5.19.95.19.9
linuxlinux_kernel>= 5.5 < 5.10.1435.10.143

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.