CVE-2022-49615: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ASoC: rt711-sdca: fix kernel NULL pointer dereference when IO error The initial settings will be written before the codec probe function. But, the rt711->component doesn't be assigned yet. If IO error happened during initial settings operations, it will cause the kernel panic. This patch changed component->dev to slave->dev to fix this issue.

Affected products

  • Linux Linux Kernel: before 5.15.56 (fixed in 5.15.56); from 5.16, before 5.18.13 (fixed in 5.18.13); version 5.19 only

Published 2025-02-26. Last modified 2026-06-17.