CVE-2022-49498
published 2025-02-26CVE-2022-49498: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Pointer…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
Pointer substream is being dereferenced on the assignment of pointer card
before substream is being null checked with the macro PCM_RUNTIME_CHECK.
Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the
the pointer check before card is assigned.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 95b30a4312545f2dde9db12bf6a425f35d5a0d77 < b2421a196cb0911ea95aec1050a0b830464c8fa6 | b2421a196cb0911ea95aec1050a0b830464c8fa6 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < f2c68c52898f623fe84518da4606538d193b0cca | f2c68c52898f623fe84518da4606538d193b0cca |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 7784d22f81a29df2ec57ca90d54f93a35cbcd1a2 | 7784d22f81a29df2ec57ca90d54f93a35cbcd1a2 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 1f2e28857be1e5c7db39bbc221332215fc5467e3 | 1f2e28857be1e5c7db39bbc221332215fc5467e3 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < b41ef7ad9238c22aa2e142f5ce4ce1a1a0d48123 | b41ef7ad9238c22aa2e142f5ce4ce1a1a0d48123 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 011b559be832194f992f73d6c0d5485f5925a10b | 011b559be832194f992f73d6c0d5485f5925a10b |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.6 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97v8-9w8c-8wvm: In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
P
ghsa_unreviewed·2025-03-17
CVE-2022-49498 [MEDIUM] CWE-476 GHSA-97v8-9w8c-8wvm: In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
P
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
Pointer substream is being dereferenced on the assignment of pointer card
before substream is being null checked with the macro PCM_RUNTIME_CHECK.
Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the
the pointer check before card is assigned.
OSV
CVE-2022-49498: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Poi
osv·2025-02-26·CVSS 5.5
CVE-2022-49498 [MEDIUM] CVE-2022-49498: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Poi
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Pointer substream is being dereferenced on the assignment of pointer card before substream is being null checked with the macro PCM_RUNTIME_CHECK. Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the the pointer check before card is assigned.
Red Hat
kernel: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49498 [MEDIUM] CWE-476 kernel: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
kernel: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Check for null pointer of pointer substream before dereferencing it
Pointer substream is being dereferenced on the assignment of pointer card
before substream is being null checked with the macro PCM_RUNTIME_CHECK.
Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the
the pointer check before card is assigned.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise
Debian
CVE-2022-49498: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
vendor_debian·2022·CVSS 5.5
CVE-2022-49498 [MEDIUM] CVE-2022-49498: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Pointer substream is being dereferenced on the assignment of pointer card before substream is being null checked with the macro PCM_RUNTIME_CHECK. Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the the pointer check before card is assigned.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/011b559be832194f992f73d6c0d5485f5925a10bhttps://git.kernel.org/stable/c/1f2e28857be1e5c7db39bbc221332215fc5467e3https://git.kernel.org/stable/c/7784d22f81a29df2ec57ca90d54f93a35cbcd1a2https://git.kernel.org/stable/c/b2421a196cb0911ea95aec1050a0b830464c8fa6https://git.kernel.org/stable/c/b41ef7ad9238c22aa2e142f5ce4ce1a1a0d48123https://git.kernel.org/stable/c/f2c68c52898f623fe84518da4606538d193b0cca
2025-02-26
Published