cbcvebase.
CVE-2022-48951
published 2024-10-21

CVE-2022-48951: In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds checks in…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds checks in snd_soc_put_volsw_sx() are only being applied to the first channel, meaning it is possible to write out of bounds values to the second channel in stereo controls. Add appropriate checks.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 038f8b7caa74d29e020949a43ca368c93f6b29b9 < 50b5f6d4d9d2d69a7498c44fd8b26e13d73d3d9850b5f6d4d9d2d69a7498c44fd8b26e13d73d3d98
linuxlinux>= 4.14.265 < 4.14.3034.14.303
linuxlinux>= 4.19.228 < 4.19.2704.19.270
linuxlinux>= 4.9.300 < 4.9.3374.9.337
linuxlinux>= 4977491e4b3aad8567f57e2a9992d251410c1db3 < cf1c225f1927891ae388562b78ced7840c3723b9cf1c225f1927891ae388562b78ced7840c3723b9
linuxlinux>= 4f1e50d6a9cf9c1b8c859d449b5031cacfa8404e < 1798b62d642e7b3d4ea3403914c3caf4e438465d1798b62d642e7b3d4ea3403914c3caf4e438465d
linuxlinux>= 4f1e50d6a9cf9c1b8c859d449b5031cacfa8404e < 97eea946b93961fffd29448dcda7398d0d51c4b297eea946b93961fffd29448dcda7398d0d51c4b2
linuxlinux>= 5.10.99 < 5.10.1605.10.160
linuxlinux>= 5.15.22 < 5.15.845.15.84
linuxlinux>= 5.16.8 < 5.175.17
linuxlinux>= 5.4.178 < 5.4.2285.4.228
linuxlinux>= 9a12fcbf3c622f9bf6b110a873d62b0cba93972e < 18a168d85eadcfd45f015b5ecd2a97801b959e4318a168d85eadcfd45f015b5ecd2a97801b959e43
linuxlinux>= 9e5c40b5706d8aae2cf70bd7e01f0b4575a642d0 < 56288987843c3cb343e81e5fa51549cbaf541bd056288987843c3cb343e81e5fa51549cbaf541bd0
linuxlinux>= c33402b056de61104b6146dedbe138ca8d7ec62b < 9796d07c753164b7e6b0d7ef23fb4482840a9ef89796d07c753164b7e6b0d7ef23fb4482840a9ef8
linuxlinux>= e8e07c5e25a29e2a6f119fd947f55d7a55eb8a13 < cf611d786796ec33da09d8c83d7d7f4e557b27decf611d786796ec33da09d8c83d7d7f4e557b27de
linuxlinux_kernel< 4.9.3374.9.337
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.