CVE-2022-49005
In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Fix bounds check for _sx controls For _sx controls the semantics of the max field is not the usual one, max is the number of steps rather than the maximum value.
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Fix bounds check for _sx controls For _sx controls the semantics of the max field is not the usual one, max is the number of steps rather than the maximum value. This means that our check in snd_soc_put_volsw_sx() needs to just check against the maximum value.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/325d94d16e3131b54bdf07356e4cd855e0d853fcPatch
- https://git.kernel.org/stable/c/46bab25cc0230df60d1c02b651cc5640a14b08dfPatch
- https://git.kernel.org/stable/c/4a95a49f26308782b4056401989ecd7768fda8faPatch
- https://git.kernel.org/stable/c/698813ba8c580efb356ace8dbf55f61dac6063a8Patch
- https://git.kernel.org/stable/c/73dce3c1d48c4662bdf3ccbde1492c2cb4bfd8cePatch
- https://git.kernel.org/stable/c/98b15c706644bebc19d2e77ccc360cc51444f6d0Patch
- https://git.kernel.org/stable/c/b50c9641897274c3faef5f95ac852f54b94be2e8Patch
- https://git.kernel.org/stable/c/e46adadf19248d59af3aa6bc52e09115bf479bf7Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.