CVE-2022-49288
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 26, 2025
Updated: Feb 27, 2025
CWE ID 416
Summary
CVE-2022-49288 is a vulnerability affecting the Linux kernel. This issue involves races among concurrent PCM buffer preallocation changes through proc files, leaving no protection against such actions. The absence of safeguards against these concurrent writes could potentially result in a Use-After-Free (UAF) scenario or other unexpected behaviors. This vulnerability has been mitigated by implementing the PCM open_mutex for the proc write operation, thereby preventing the occurrence of these races and securing the PCM stream open and subsequent operations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Linux Kernel
Affected Vendors
- LINUX