ZeroHour

CVE-2022-1048

CVSS 3.1
7.0 high
EPSS
<1%p15
Published
()
Modified
Description

A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Vendors
linuxredhatdebiannetapp
Products
linux kernel, enterprise linux, debian linux, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h300e firmware, h500e firmware, h700e firmware, h410c firmware
Weakness
CWE-416, CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.