CVE-2022-49288
HIGHLinux Kernel - Use-After-Free in ALSA PCM Prealloc Proc Write
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).
References (8)
Core 8
Core References
Scores
CVSS v3
7.8
EPSS
0.0026
EPSS Percentile
17.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (26)
linux/Kernel
2.6.12 - 4.14.279linux
linux/Kernel
4.15.0 - 4.19.243linux
linux/Kernel
4.20.0 - 5.4.193linux
linux/Kernel
5.11.0 - 5.15.32linux
linux/Kernel
5.16.0 - 5.16.18linux
linux/Kernel
5.17.0 - 5.17.1linux
linux/Kernel
5.5.0 - 5.10.109linux
Linux/Linux
< 2.6.12
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 37b12c16beb6f6c1c3c678c1aacbc46525c250f7
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 51fce708ab8986a9879ee5da946a2cc120f1036d
... and 16 more
Published
Feb 26, 2025
Tracked Since
Feb 18, 2026