CVE-2022-49288

Source
https://cve.org/CVERecord?id=CVE-2022-49288
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49288.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49288
Downstream
Related
Published
2025-02-26T01:56:26.550Z
Modified
2026-03-20T12:22:19.608965Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ALSA: pcm: Fix races among concurrent prealloc proc writes
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: Fix races among concurrent prealloc proc writes

We have no protection against concurrent PCM buffer preallocation changes via proc files, and it may potentially lead to UAF or some weird problem. This patch applies the PCM open_mutex to the proc write operation for avoiding the racy proc writes and the PCM stream open (and further operations).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49288.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
e7786c445bb67a9a6e64f66ebd6b7215b153ff7d
Fixed
e14dca613e0a6ddc2bf6e360f16936a9f865205b
Fixed
37b12c16beb6f6c1c3c678c1aacbc46525c250f7
Fixed
b560d670c87d7d40b3cf6949246fa4c7aa65a00a
Fixed
51fce708ab8986a9879ee5da946a2cc120f1036d
Fixed
a21d2f323b5a978dedf9ff1d50f101f85e39b3f2
Fixed
5ed8f8e3c4e59d0396b9ccf2e639711e24295bb6
Fixed
69534c48ba8ce552ce383b3dfdb271ffe51820c3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49288.json"