PT-2024-11857 · Linux+5 · Linux Kernel+5

Kernel Test Robot

·

Published

2022-11-18

·

Updated

2025-09-29

·

CVE-2022-48994

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns a function prototype mismatch in the snd seq expand var event function within the ALSA seq module of the Linux kernel. This mismatch can lead to a failure at runtime, manifesting as either a kernel panic or a thread being killed, when using Clang's kernel control flow integrity (kCFI, CONFIG CFI CLANG) to validate indirect call targets against expected function pointer prototypes. The functions seq copy in user() and seq copy in kernel() did not have prototypes matching snd seq dump func t, which has been adjusted and the casts removed, with no resulting binary output differences. This was discovered using Clang's new -Wcast-function-type-strict flag.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-1066
BDU:2025-14267
CVE-2022-48994
OESA-2024-2323
OESA-2024-2324
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_4131-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:4082-1
SUSE-SU-2024:4131-1
SUSE-SU-2024:4364-1
USN-7332-1
USN-7332-2
USN-7332-3
USN-7333-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse
Ubuntu