cbcvebase.
CVE-2022-49617
published 2025-02-26

CVE-2022-49617: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration fails…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration fails, typically because of deferred probes, the device properties added for headset codecs are not removed, which leads to kernel oopses in driver bind/unbind tests. We already clean-up the device properties when the card is removed, this code can be moved as a helper and called upon card registration errors.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 52db12d193d45728e738df6119702cba08fd46a2 < f2556ce6b35ae0fc72000a4daa21ded12665e2f2f2556ce6b35ae0fc72000a4daa21ded12665e2f2
linuxlinux>= 52db12d193d45728e738df6119702cba08fd46a2 < 09bca0ffc95c50369f1345d80ecfaca51864126f09bca0ffc95c50369f1345d80ecfaca51864126f
linuxlinux>= 52db12d193d45728e738df6119702cba08fd46a2 < fe154c4ff376bc31041c6441958a08243df09c99fe154c4ff376bc31041c6441958a08243df09c99
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.7 < 5.15.565.15.56

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.