CVE-2022-49498
Last modified
CVE-2022-49498 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Pointer substream is being dereferenced on the assignment of pointer card before substream is being null checked with the macro PCM_RUNTIME_CHECK. Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the the pointer check before card is assigned.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Check for null pointer of pointer substream before dereferencing it Pointer substream is being dereferenced on the assignment of pointer card before substream is being null checked with the macro PCM_RUNTIME_CHECK. Although PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the the pointer check before card is assigned.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.6, < 5.10.121 |
| Linux | Linux Kernel | >= 5.11, < 5.15.46 |
| Linux | Linux Kernel | >= 5.16, < 5.17.14 |
| Linux | Linux Kernel | >= 5.18, < 5.18.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-49498?
How severe is CVE-2022-49498?
How do I fix CVE-2022-49498?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-49492In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49493In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-49494In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49495In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49496In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49497In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49499In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-4950Several WordPress plugins developed by Cool Plugins are vuln…8.8
- CVE-2022-49500In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49501In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-49502In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2022-49503In the Linux kernel, the following vulnerability has been re…7.1
Are you affected by CVE-2022-49498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
