CVE-2022-49288
published 2025-02-26CVE-2022-49288: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix races among concurrent prealloc proc writes
We have no protection against concurrent PCM buffer preallocation
changes via proc files, and it may potentially lead to UAF or some
weird problem. This patch applies the PCM open_mutex to the proc
write operation for avoiding the racy proc writes and the PCM stream
open (and further operations).
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e7786c445bb67a9a6e64f66ebd6b7215b153ff7d | e7786c445bb67a9a6e64f66ebd6b7215b153ff7d |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e14dca613e0a6ddc2bf6e360f16936a9f865205b | e14dca613e0a6ddc2bf6e360f16936a9f865205b |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 37b12c16beb6f6c1c3c678c1aacbc46525c250f7 | 37b12c16beb6f6c1c3c678c1aacbc46525c250f7 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b560d670c87d7d40b3cf6949246fa4c7aa65a00a | b560d670c87d7d40b3cf6949246fa4c7aa65a00a |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 51fce708ab8986a9879ee5da946a2cc120f1036d | 51fce708ab8986a9879ee5da946a2cc120f1036d |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a21d2f323b5a978dedf9ff1d50f101f85e39b3f2 | a21d2f323b5a978dedf9ff1d50f101f85e39b3f2 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5ed8f8e3c4e59d0396b9ccf2e639711e24295bb6 | 5ed8f8e3c4e59d0396b9ccf2e639711e24295bb6 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 69534c48ba8ce552ce383b3dfdb271ffe51820c3 | 69534c48ba8ce552ce383b3dfdb271ffe51820c3 |
| linux | linux_kernel | < 4.14.279 | 4.14.279 |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 4.15 < 4.19.243 | 4.19.243 |
| linux | linux_kernel | >= 4.20 < 5.4.193 | 5.4.193 |
| linux | linux_kernel | >= 5.11 < 5.15.32 | 5.15.32 |
| linux | linux_kernel | >= 5.16 < 5.16.18 | 5.16.18 |
| linux | linux_kernel | >= 5.17 < 5.17.1 | 5.17.1 |
| linux | linux_kernel | >= 5.5 < 5.10.109 | 5.10.109 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87qr-3hp3-x583: In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix races among concurrent prealloc proc writes
We have no protection
ghsa_unreviewed·2025-02-27
CVE-2022-49288 [HIGH] CWE-416 GHSA-87qr-3hp3-x583: In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix races among concurrent prealloc proc writes
We have no protection
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix races among concurrent prealloc proc writes
We have no protection against concurrent PCM buffer preallocation
changes via proc files, and it may potentially lead to UAF or some
weird problem. This patch applies the PCM open_mutex to the proc
write operation for avoiding the racy proc writes and the PCM stream
open (and further operations).
OSV
CVE-2022-49288: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection a
osv·2025-02-26·CVSS 7.8
CVE-2022-49288 [HIGH] CVE-2022-49288: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection a
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).
Red Hat
kernel: ALSA: pcm: Fix races among concurrent prealloc proc writes
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49288 [HIGH] CWE-362 kernel: ALSA: pcm: Fix races among concurrent prealloc proc writes
kernel: ALSA: pcm: Fix races among concurrent prealloc proc writes
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix races among concurrent prealloc proc writes
We have no protection against concurrent PCM buffer preallocation
changes via proc files, and it may potentially lead to UAF or some
weird problem. This patch applies the PCM open_mutex to the proc
write operation for avoiding the racy proc writes and the PCM stream
open (and further operations).
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Lin
Debian
CVE-2022-49288: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
vendor_debian·2022·CVSS 7.8
CVE-2022-49288 [HIGH] CVE-2022-49288: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/37b12c16beb6f6c1c3c678c1aacbc46525c250f7https://git.kernel.org/stable/c/51fce708ab8986a9879ee5da946a2cc120f1036dhttps://git.kernel.org/stable/c/5ed8f8e3c4e59d0396b9ccf2e639711e24295bb6https://git.kernel.org/stable/c/69534c48ba8ce552ce383b3dfdb271ffe51820c3https://git.kernel.org/stable/c/a21d2f323b5a978dedf9ff1d50f101f85e39b3f2https://git.kernel.org/stable/c/b560d670c87d7d40b3cf6949246fa4c7aa65a00ahttps://git.kernel.org/stable/c/e14dca613e0a6ddc2bf6e360f16936a9f865205bhttps://git.kernel.org/stable/c/e7786c445bb67a9a6e64f66ebd6b7215b153ff7d
2025-02-26
Published