PT-2025-8471 · Linux+4 · Linux Kernel+4
Amadeusz Sławiński
·
Published
2022-04-12
·
Updated
2025-04-25
·
CVE-2022-49538
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A issue in the Linux kernel has been identified where the input dev can be unregistered while calling snd jack report when using ASoC, leading to a NULL pointer dereference. This occurs due to lack of serialization in access to input dev.
Recommendations
To resolve this issue, apply a patch that implements a mutex lock to serialize access to input dev, preventing the NULL pointer dereference.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse