CVE-2022-49005

MEDIUM

Linux Kernel 4.9.300-4.9.335 - Integer Overflow in ASoC Volume Control

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Fix bounds check for _sx controls For _sx controls the semantics of the max field is not the usual one, max is the number of steps rather than the maximum value. This means that our check in snd_soc_put_volsw_sx() needs to just check against the maximum value.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (35)
linux/Kernel < 4.9.335linux
linux/Kernel 4.10.0 - 4.14.301linux
linux/Kernel 4.15.0 - 4.19.268linux
linux/Kernel 4.20.0 - 5.4.226linux
linux/Kernel 5.11.0 - 5.15.82linux
linux/Kernel 5.16.0 - 6.0.12linux
linux/Kernel 5.5.0 - 5.10.158linux
Linux/Linux < 5.17
Linux/Linux 038f8b7caa74d29e020949a43ca368c93f6b29b9 - b50c9641897274c3faef5f95ac852f54b94be2e8
Linux/Linux 4.14.265 - 4.14.301
... and 25 more
Published Oct 21, 2024
Tracked Since Feb 18, 2026