PT-2022-7662 · Linux+5 · Linux Kernel+5
Alexander Sergeyev
·
Published
2022-01-26
·
Updated
2025-09-29
·
CVE-2022-48735
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the use of memory after it has been freed in the ALSA sound subsystem of the Linux kernel. This is due to a problem with the registration and unregistration of LED class devices created by HD-audio codec drivers. The devres release does not work correctly in this case, leading to a NULL dereference or a use-after-free (UAF) for a stale set brightness delay callback. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use After Free
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse