PT-2024-9261 · Linux+5 · Linux Kernel+5

Mark Brown

·

Published

2022-11-08

·

Updated

2025-09-29

·

CVE-2022-48738

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the ASoC: ops component of the Linux kernel, where it fails to validate that the values being set are within the range advertised to userspace as being valid. This can lead to out-of-bounds values being accepted, potentially causing issues. The problem is resolved by rejecting any values that are out of range in the snd soc put volsw() function. There is also a mention of a potential buffer overflow error, which could allow an attacker to cause a denial of service.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2024-10949
CESA-2022_7683
CVE-2022-48738
OESA-2024-1835
OPENSUSE-SU-2024_2362-1
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2024:2362-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2384-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse