CVE-2022-49291: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent hw_params and hw_free calls Currently we have neither proper check nor protection against the concurrent calls of PCM hw_params and hw_free ioctls, which may result in a UAF. Since the existing PCM stream lock can't be used for protecting the whole ioctl operations, we need a new mutex to protect those racy calls. This patch introduced a new mutex, runtime->buffer_mutex, and applies it to both hw_params and hw_free ioctl code paths. Along with it, the both functions are slightly modified (the mmap_count check is moved into the state-check block) for code simplicity.

Affected products

  • Linux Linux Kernel: before 4.14.279 (fixed in 4.14.279); from 4.15, before 4.19.243 (fixed in 4.19.243); from 4.20, before 5.4.193 (fixed in 5.4.193); from 5.5, before 5.10.109 (fixed in 5.10.109); from 5.11, before 5.15.32 (fixed in 5.15.32); from 5.16, before 5.16.18 (fixed in 5.16.18); …

Published 2025-02-26. Last modified 2026-06-17.