cbcvebase.
CVE-2022-49288
published 2025-02-26

CVE-2022-49288: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e7786c445bb67a9a6e64f66ebd6b7215b153ff7de7786c445bb67a9a6e64f66ebd6b7215b153ff7d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e14dca613e0a6ddc2bf6e360f16936a9f865205be14dca613e0a6ddc2bf6e360f16936a9f865205b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 37b12c16beb6f6c1c3c678c1aacbc46525c250f737b12c16beb6f6c1c3c678c1aacbc46525c250f7
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b560d670c87d7d40b3cf6949246fa4c7aa65a00ab560d670c87d7d40b3cf6949246fa4c7aa65a00a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 51fce708ab8986a9879ee5da946a2cc120f1036d51fce708ab8986a9879ee5da946a2cc120f1036d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a21d2f323b5a978dedf9ff1d50f101f85e39b3f2a21d2f323b5a978dedf9ff1d50f101f85e39b3f2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5ed8f8e3c4e59d0396b9ccf2e639711e24295bb65ed8f8e3c4e59d0396b9ccf2e639711e24295bb6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 69534c48ba8ce552ce383b3dfdb271ffe51820c369534c48ba8ce552ce383b3dfdb271ffe51820c3
linuxlinux_kernel< 4.14.2794.14.279
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.15 < 4.19.2434.19.243
linuxlinux_kernel>= 4.20 < 5.4.1935.4.193
linuxlinux_kernel>= 5.11 < 5.15.325.15.32
linuxlinux_kernel>= 5.16 < 5.16.185.16.18
linuxlinux_kernel>= 5.17 < 5.17.15.17.1
linuxlinux_kernel>= 5.5 < 5.10.1095.10.109

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.