PT-2025-8196 · Linux+4 · Linux Kernel+4

Ammar Faizi

·

Published

2022-02-24

·

Updated

2025-09-29

·

CVE-2022-49268

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the version that includes the fix for the NULL pointer dereference bug.
Description A NULL pointer dereference bug has been identified in the Linux kernel, specifically in the ASoC: SOF: Intel component. This issue occurs when the snd dma alloc pages() function returns -ENOMEM, and subsequently, snd dma free pages() is called, leading to a NULL pointer dereference. The error is indicated by a message in the dmesg log, including an error code of -12 and a BUG report detailing a kernel NULL pointer dereference.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference bug. As a temporary workaround, consider disabling the dma free noncontiguous() function or restricting its use until a patched version of the kernel is available. However, since the provided information does not specify the exact version that includes the fix, it is recommended to check for and apply the latest kernel updates. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-04309
CESA-2022_7683
CVE-2022-49268
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse