CVE-2022-49538

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-49538
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49538.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49538
Downstream
Related
Published
2025-02-26T07:01:29Z
Modified
2025-10-01T20:16:38Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: jack: Access input_dev under mutex

It is possible when using ASoC that inputdev is unregistered while calling sndjackreport, which causes NULL pointer dereference. In order to prevent this serialize access to inputdev using mutex lock.

References

Affected packages