PT-2025-18489 · Linux+2 · Linux Kernel+2

Published

2022-11-12

·

Updated

2025-07-10

·

CVE-2022-49772

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel related to the ALSA: usb-audio component. The issue concerns the snd usbmidi output open() function, which contains a check for a NULL port using snd BUG ON(). However, this check can be triggered when a device provides an invalid endpoint setup in its descriptor, causing the driver to skip allocation. The check itself is valid, but the use of snd BUG ON() can be misleading, suggesting a real bug. This was recently detected by syzbot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Improper Resource Release

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02634
CVE-2022-49772
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01982-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:01995-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01982-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Linux Kernel
Suse