CVE-2022-49288

HIGH

Linux Kernel - Use-After-Free in ALSA PCM Prealloc Proc Write

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent prealloc proc writes We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).

Scores

CVSS v3 7.8
EPSS 0.0026
EPSS Percentile 17.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (26)
linux/Kernel 2.6.12 - 4.14.279linux
linux/Kernel 4.15.0 - 4.19.243linux
linux/Kernel 4.20.0 - 5.4.193linux
linux/Kernel 5.11.0 - 5.15.32linux
linux/Kernel 5.16.0 - 5.16.18linux
linux/Kernel 5.17.0 - 5.17.1linux
linux/Kernel 5.5.0 - 5.10.109linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 37b12c16beb6f6c1c3c678c1aacbc46525c250f7
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 51fce708ab8986a9879ee5da946a2cc120f1036d
... and 16 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026