CVE-2022-48951: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() The bounds checks in snd_soc_put_volsw_sx() are only being applied to the first channel, meaning it is possible to write out of bounds values to the second channel in stereo controls. Add appropriate checks.
Affected products
- Linux Linux Kernel: before 4.9.337 (fixed in 4.9.337); from 4.10, before 4.14.303 (fixed in 4.14.303); from 4.15, before 4.19.270 (fixed in 4.19.270); from 4.20, before 5.4.228 (fixed in 5.4.228); from 5.5, before 5.10.160 (fixed in 5.10.160); from 5.11, before 5.15.84 (fixed in 5.15.84); …
Published 2024-10-21. Last modified 2026-06-17.