Executive Summary

Informations
Name CVE-2022-1048 First vendor Publication 2022-04-29
Vendor Cve Last vendor Modification 2024-01-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 7
Base Score 7 Environmental Score 7
impact SubScore 5.9 Temporal Score 7
Exploitabality Sub Score 1
 
Attack Vector Local Attack Complexity High
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 6.9 Attack Range Local
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1048

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-416 Use After Free
50 % CWE-362 Race Condition

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 7
Os 2
Os 3461
Os 1

Sources (Detail)

https://lore.kernel.org/lkml/20220322170720.3529-5-tiwai%40suse.de/T/#m1d3b79...
Source Url
CONFIRM https://security.netapp.com/advisory/ntap-20220629-0001/
DEBIAN https://www.debian.org/security/2022/dsa-5127
https://www.debian.org/security/2022/dsa-5173
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2066706

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
Date Informations
2024-03-12 13:21:48
  • Multiple Updates
2024-02-02 02:30:47
  • Multiple Updates
2024-02-01 12:25:34
  • Multiple Updates
2024-01-21 09:27:44
  • Multiple Updates
2024-01-12 02:23:19
  • Multiple Updates
2023-12-29 02:21:16
  • Multiple Updates
2023-11-22 02:20:40
  • Multiple Updates
2023-11-09 17:31:44
  • Multiple Updates
2023-11-07 21:32:31
  • Multiple Updates
2023-09-29 13:15:16
  • Multiple Updates
2023-09-05 13:25:13
  • Multiple Updates
2023-09-05 01:25:01
  • Multiple Updates
2023-09-02 13:23:33
  • Multiple Updates
2023-09-02 01:25:25
  • Multiple Updates
2023-08-12 05:28:30
  • Multiple Updates
2023-08-12 01:24:39
  • Multiple Updates
2023-08-11 05:28:28
  • Multiple Updates
2023-08-11 01:25:28
  • Multiple Updates
2023-08-06 05:27:47
  • Multiple Updates
2023-08-06 01:24:22
  • Multiple Updates
2023-08-04 21:28:08
  • Multiple Updates
2023-08-04 13:20:01
  • Multiple Updates
2023-08-04 01:24:44
  • Multiple Updates
2023-07-14 13:20:03
  • Multiple Updates
2023-07-14 01:24:30
  • Multiple Updates
2023-06-06 13:11:49
  • Multiple Updates
2023-05-17 13:05:18
  • Multiple Updates
2023-04-13 02:09:43
  • Multiple Updates
2023-04-07 13:06:48
  • Multiple Updates
2023-03-29 02:21:59
  • Multiple Updates
2023-03-28 12:24:41
  • Multiple Updates
2023-03-25 02:09:33
  • Multiple Updates
2023-01-25 02:09:43
  • Multiple Updates
2023-01-20 02:09:13
  • Multiple Updates
2022-12-17 00:27:52
  • Multiple Updates
2022-12-14 21:27:36
  • Multiple Updates
2022-10-11 13:11:14
  • Multiple Updates
2022-10-11 01:24:05
  • Multiple Updates
2022-09-09 02:09:08
  • Multiple Updates
2022-07-04 17:27:20
  • Multiple Updates
2022-06-30 00:27:26
  • Multiple Updates
2022-06-23 12:54:17
  • Multiple Updates
2022-06-23 02:04:37
  • Multiple Updates
2022-05-11 21:23:03
  • Multiple Updates
2022-05-03 17:22:54
  • Multiple Updates
2022-04-30 09:22:53
  • Multiple Updates
2022-04-29 21:22:55
  • First insertion