PT-2025-40116 · Linux+4 · Linux Kernel+4
Published
2022-10-27
·
Updated
2025-10-23
·
CVE-2022-50431
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak was identified in the
i2sbus add dev() function within the ALSA subsystem related to the AOA (Accessories Over Audio) driver. The dev set name() function in soundbus add one() allocates memory for a name, which was not being freed when of device register() failed. This issue is addressed by calling soundbus dev put() to release the reference, allowing the memory to be freed during kobject cleanup when the reference count reaches zero. Resources are also freed in i2sbus release dev(), enabling a direct return of 0.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse