Skip to content

kernel CVE-2022-1048

Moderate
arnaldo2792 published GHSA-37fp-5pw6-8wj5 Apr 25, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.7.2

Patched versions

1.7.2

Description

A use-after-free flaw was found in the Linux kernel's sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Severity

Moderate

CVE ID

CVE-2022-1048

Weaknesses

No CWEs