PT-2025-8471 · Linux+4 · Linux Kernel+4

Amadeusz Sławiński

·

Published

2022-04-12

·

Updated

2025-04-25

·

CVE-2022-49538

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A issue in the Linux kernel has been identified where the input dev can be unregistered while calling snd jack report when using ASoC, leading to a NULL pointer dereference. This occurs due to lack of serialization in access to input dev.
Recommendations To resolve this issue, apply a patch that implements a mutex lock to serialize access to input dev, preventing the NULL pointer dereference.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02225
CESA-2022_7683
CVE-2022-49538
OESA-2025-1447
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:1176-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse