CVE-2022-49545

Source
https://cve.org/CVERecord?id=CVE-2022-49545
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49545.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49545
Downstream
Related
Published
2025-02-26T02:13:58.363Z
Modified
2026-04-11T12:44:13.821280Z
Summary
ALSA: usb-audio: Cancel pending work at closing a MIDI substream
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Cancel pending work at closing a MIDI substream

At closing a USB MIDI output substream, there might be still a pending work, which would eventually access the rawmidi runtime object that is being released. For fixing the race, make sure to cancel the pending work at closing.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49545.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
40bdb5ec957aca5c5c1924602bef6b0ab18e22d3
Fixed
11868ca21585561659c2575b0d6508ef8e9c4291
Fixed
5e5fe2b6065541c6216a7a003b0cddf386be0d2d
Fixed
517dcef4d2dda0132648f1e4c079ed17bba4d1a4
Fixed
0125de38122f0f66bf61336158d12a1aabfe6425

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49545.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.12
Fixed
5.10.121
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.46
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.14
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49545.json"