CVE-2022-49617
published 2025-02-26CVE-2022-49617: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration fails…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof_sdw: handle errors on card registration
If the card registration fails, typically because of deferred probes,
the device properties added for headset codecs are not removed, which
leads to kernel oopses in driver bind/unbind tests.
We already clean-up the device properties when the card is removed,
this code can be moved as a helper and called upon card registration
errors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.14-1 (bookworm) | linux 5.18.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 52db12d193d45728e738df6119702cba08fd46a2 < f2556ce6b35ae0fc72000a4daa21ded12665e2f2 | f2556ce6b35ae0fc72000a4daa21ded12665e2f2 |
| linux | linux | >= 52db12d193d45728e738df6119702cba08fd46a2 < 09bca0ffc95c50369f1345d80ecfaca51864126f | 09bca0ffc95c50369f1345d80ecfaca51864126f |
| linux | linux | >= 52db12d193d45728e738df6119702cba08fd46a2 < fe154c4ff376bc31041c6441958a08243df09c99 | fe154c4ff376bc31041c6441958a08243df09c99 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 5.16 < 5.18.13 | 5.18.13 |
| linux | linux_kernel | >= 5.7 < 5.15.56 | 5.15.56 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ASoC: Intel: sof_sdw: handle errors on card registration
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49617 [MEDIUM] CWE-20 kernel: ASoC: Intel: sof_sdw: handle errors on card registration
kernel: ASoC: Intel: sof_sdw: handle errors on card registration
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof_sdw: handle errors on card registration
If the card registration fails, typically because of deferred probes,
the device properties added for headset codecs are not removed, which
leads to kernel oopses in driver bind/unbind tests.
We already clean-up the device properties when the card is removed,
this code can be moved as a helper and called upon card registration
errors.
A flaw was found in the Intel SoundWire (sof_sdw) driver within the Linux kernel's ASoC subsystem. When a sound card registration fails, often due to deferred probing, the driver does not clean up associated device properties for headset codecs. This incomplete cleanup c
Debian
CVE-2022-49617: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel...
vendor_debian·2022·CVSS 5.5
CVE-2022-49617 [MEDIUM] CVE-2022-49617: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel...
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration fails, typically because of deferred probes, the device properties added for headset codecs are not removed, which leads to kernel oopses in driver bind/unbind tests. We already clean-up the device properties when the card is removed, this code can be moved as a helper and called upon card registration errors.
Scope: local
bookworm: resolved (fixed in 5.18.14-1)
bullseye: open
forky: resolved (fixed in 5.18.14-1)
sid: resolved (fixed in 5.18.14-1)
trixie: resolved (fixed in 5.18.14-1)
GHSA
GHSA-264c-vhxj-p55j: In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof_sdw: handle errors on card registration
If the card registratio
ghsa_unreviewed·2025-10-23
CVE-2022-49617 [MEDIUM] GHSA-264c-vhxj-p55j: In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof_sdw: handle errors on card registration
If the card registratio
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof_sdw: handle errors on card registration
If the card registration fails, typically because of deferred probes,
the device properties added for headset codecs are not removed, which
leads to kernel oopses in driver bind/unbind tests.
We already clean-up the device properties when the card is removed,
this code can be moved as a helper and called upon card registration
errors.
OSV
CVE-2022-49617: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration
osv·2025-02-26·CVSS 5.5
CVE-2022-49617 [MEDIUM] CVE-2022-49617: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: handle errors on card registration If the card registration fails, typically because of deferred probes, the device properties added for headset codecs are not removed, which leads to kernel oopses in driver bind/unbind tests. We already clean-up the device properties when the card is removed, this code can be moved as a helper and called upon card registration errors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-26
Published