ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface()
Published May 3, 2024
7.1
HIGHCVSS 3.1
EPSS 0.24%
Description
There may be a bad USB audio device with a USB ID of (0x04fa, 0x4201) and the number of it's interfaces less than 4, an out-of-bounds read bug occurs when parsing the interface descriptor for this device.
Fix this by checking the number of interfaces.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.26StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.26
- Version 4.14.293StatusunaffectedConstraints<=4.14.*
- Version 4.19.258StatusunaffectedConstraints<=4.19.*
- Version 4.9.328StatusunaffectedConstraints<=4.9.*
- Version 5.10.143StatusunaffectedConstraints<=5.10.*
- Version 5.15.68StatusunaffectedConstraints<=5.15.*
- Version 5.19.9StatusunaffectedConstraints<=5.19.*
- Version 5.4.213StatusunaffectedConstraints<=5.4.*
- Version 6.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.9.328
- ≥ 4.10 · < 4.14.293
- ≥ 4.15 · < 4.19.258
- ≥ 4.20 · < 5.4.213
- ≥ 5.5 · < 5.10.143
- ≥ 5.11 · < 5.15.68
- ≥ 5.16 · < 5.19.9
- 6.0
- 6.0
- 6.0
- 6.0
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-0:3.10.0-1160.141.1.el7
Fixed · RHSA-2025:17161
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-rt-0:3.10.0-1160.140.1.rt56.1292.el7
Fixed · RHSA-2025:17109
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.178.1.el8_2
Fixed · RHSA-2025:23445
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.179.1.el8_4
Fixed · RHSA-2025:22752
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.179.1.el8_4
Fixed · RHSA-2025:22752
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.168.1.el8_6
Fixed · RHSA-2025:21084
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.168.1.el8_6
Fixed · RHSA-2025:21084
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.168.1.el8_6
Fixed · RHSA-2025:21084
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-0:5.14.0-70.153.1.el9_0
Fixed · RHSA-2025:21091
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-rt-0:5.14.0-70.153.1.rt21.225.el9_0
Fixed · RHSA-2025:21136
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-0:3.10.0-1160.141.1.el7 | Fixed | RHSA-2025:17161 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-rt-0:3.10.0-1160.140.1.rt56.1292.el7 | Fixed | RHSA-2025:17109 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.178.1.el8_2 | Fixed | RHSA-2025:23445 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.179.1.el8_4 | Fixed | RHSA-2025:22752 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.179.1.el8_4 | Fixed | RHSA-2025:22752 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.168.1.el8_6 | Fixed | RHSA-2025:21084 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.168.1.el8_6 | Fixed | RHSA-2025:21084 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.168.1.el8_6 | Fixed | RHSA-2025:21084 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-0:5.14.0-70.153.1.el9_0 | Fixed | RHSA-2025:21091 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-rt-0:5.14.0-70.153.1.rt21.225.el9_0 | Fixed | RHSA-2025:21136 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-48701 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2278950 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53580 Advisory
- https://git.kernel.org/stable/c/0492798bf8dfcc09c9337a1ba065da1d1ca68712 Patch
- https://git.kernel.org/stable/c/2a308e415d247a23d4d64c964c02e782eede2936 Patch
- https://git.kernel.org/stable/c/6123bec8480d23369e2ee0b2208611619f269faf Patch
- https://git.kernel.org/stable/c/8293e61bbf908b18ff9935238d4fc2ad359e3fe0 Patch
- https://git.kernel.org/stable/c/91904870370fd986c29719846ed76d559de43251 Patch
- https://git.kernel.org/stable/c/98e8e67395cc6d0cdf3a771f86ea42d0ee6e59dd Patch
- https://git.kernel.org/stable/c/b970518014f2f0f6c493fb86c1e092b936899061 Patch
- https://git.kernel.org/stable/c/e53f47f6c1a56d2af728909f1cb894da6b43d9bf Patch
- https://nvd.nist.gov/vuln/detail/CVE-2022-48701
- https://www.cve.org/CVERecord?id=CVE-2022-48701
Change history (0)
No recorded changes yet.