CVE-2022-48701
HIGHLinux Kernel < 4.9.328 - Out-of-Bounds Read
Title source: ruleDescription
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() There may be a bad USB audio device with a USB ID of (0x04fa, 0x4201) and the number of it's interfaces less than 4, an out-of-bounds read bug occurs when parsing the interface descriptor for this device. Fix this by checking the number of interfaces.
References (8)
Scores
CVSS v3
7.1
EPSS
0.0001
EPSS Percentile
0.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Classification
CWE
CWE-125
Status
published
Affected Products (12)
linux/linux_kernel
< 4.9.328
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/Kernel
< 4.9.328linux
linux/Kernel
< 4.14.293linux
linux/Kernel
< 4.19.258linux
linux/Kernel
< 5.4.213linux
linux/Kernel
< 5.10.143linux
linux/Kernel
< 5.15.68linux
linux/Kernel
< 5.19.9linux
Timeline
Published
May 03, 2024
Tracked Since
Feb 18, 2026