CVE-2022-48951
published 2024-10-21CVE-2022-48951: In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds checks in…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
The bounds checks in snd_soc_put_volsw_sx() are only being applied to the
first channel, meaning it is possible to write out of bounds values to the
second channel in stereo controls. Add appropriate checks.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 038f8b7caa74d29e020949a43ca368c93f6b29b9 < 50b5f6d4d9d2d69a7498c44fd8b26e13d73d3d98 | 50b5f6d4d9d2d69a7498c44fd8b26e13d73d3d98 |
| linux | linux | >= 4.14.265 < 4.14.303 | 4.14.303 |
| linux | linux | >= 4.19.228 < 4.19.270 | 4.19.270 |
| linux | linux | >= 4.9.300 < 4.9.337 | 4.9.337 |
| linux | linux | >= 4977491e4b3aad8567f57e2a9992d251410c1db3 < cf1c225f1927891ae388562b78ced7840c3723b9 | cf1c225f1927891ae388562b78ced7840c3723b9 |
| linux | linux | >= 4f1e50d6a9cf9c1b8c859d449b5031cacfa8404e < 1798b62d642e7b3d4ea3403914c3caf4e438465d | 1798b62d642e7b3d4ea3403914c3caf4e438465d |
| linux | linux | >= 4f1e50d6a9cf9c1b8c859d449b5031cacfa8404e < 97eea946b93961fffd29448dcda7398d0d51c4b2 | 97eea946b93961fffd29448dcda7398d0d51c4b2 |
| linux | linux | >= 5.10.99 < 5.10.160 | 5.10.160 |
| linux | linux | >= 5.15.22 < 5.15.84 | 5.15.84 |
| linux | linux | >= 5.16.8 < 5.17 | 5.17 |
| linux | linux | >= 5.4.178 < 5.4.228 | 5.4.228 |
| linux | linux | >= 9a12fcbf3c622f9bf6b110a873d62b0cba93972e < 18a168d85eadcfd45f015b5ecd2a97801b959e43 | 18a168d85eadcfd45f015b5ecd2a97801b959e43 |
| linux | linux | >= 9e5c40b5706d8aae2cf70bd7e01f0b4575a642d0 < 56288987843c3cb343e81e5fa51549cbaf541bd0 | 56288987843c3cb343e81e5fa51549cbaf541bd0 |
| linux | linux | >= c33402b056de61104b6146dedbe138ca8d7ec62b < 9796d07c753164b7e6b0d7ef23fb4482840a9ef8 | 9796d07c753164b7e6b0d7ef23fb4482840a9ef8 |
| linux | linux | >= e8e07c5e25a29e2a6f119fd947f55d7a55eb8a13 < cf611d786796ec33da09d8c83d7d7f4e557b27de | cf611d786796ec33da09d8c83d7d7f4e557b27de |
| linux | linux_kernel | < 4.9.337 | 4.9.337 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.162-1 | 5.10.162-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 4.10 < 4.14.303 | 4.14.303 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48951: In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds ch
osv·2024-10-21·CVSS 7.8
CVE-2022-48951 [HIGH] CVE-2022-48951: In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds ch
In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds checks in snd_soc_put_volsw_sx() are only being applied to the first channel, meaning it is possible to write out of bounds values to the second channel in stereo controls. Add appropriate checks.
GHSA
GHSA-vwjf-jh23-hhpx: In the Linux kernel, the following vulnerability has been resolved:
ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
The bounds
ghsa_unreviewed·2024-10-21
CVE-2022-48951 [HIGH] CWE-787 GHSA-vwjf-jh23-hhpx: In the Linux kernel, the following vulnerability has been resolved:
ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
The bounds
In the Linux kernel, the following vulnerability has been resolved:
ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
The bounds checks in snd_soc_put_volsw_sx() are only being applied to the
first channel, meaning it is possible to write out of bounds values to the
second channel in stereo controls. Add appropriate checks.
Red Hat
kernel: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
vendor_redhat·2024-10-21·CVSS 7.8
CVE-2022-48951 [HIGH] CWE-787 kernel: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
kernel: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
In the Linux kernel, the following vulnerability has been resolved:
ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
The bounds checks in snd_soc_put_volsw_sx() are only being applied to the
first channel, meaning it is possible to write out of bounds values to the
second channel in stereo controls. Add appropriate checks.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2022-48951: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: ...
vendor_debian·2022·CVSS 7.8
CVE-2022-48951 [HIGH] CVE-2022-48951: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: ...
In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds checks in snd_soc_put_volsw_sx() are only being applied to the first channel, meaning it is possible to write out of bounds values to the second channel in stereo controls. Add appropriate checks.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.162-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/1798b62d642e7b3d4ea3403914c3caf4e438465dhttps://git.kernel.org/stable/c/18a168d85eadcfd45f015b5ecd2a97801b959e43https://git.kernel.org/stable/c/50b5f6d4d9d2d69a7498c44fd8b26e13d73d3d98https://git.kernel.org/stable/c/56288987843c3cb343e81e5fa51549cbaf541bd0https://git.kernel.org/stable/c/9796d07c753164b7e6b0d7ef23fb4482840a9ef8https://git.kernel.org/stable/c/97eea946b93961fffd29448dcda7398d0d51c4b2https://git.kernel.org/stable/c/cf1c225f1927891ae388562b78ced7840c3723b9https://git.kernel.org/stable/c/cf611d786796ec33da09d8c83d7d7f4e557b27de
2024-10-21
Published