CVE-2022-49545

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Cancel pending work at closing a MIDI substream At closing a USB MIDI output substream, there might be still a pending work, which would eventually access the rawmidi runtime object that is being released. For fixing the race, make sure to cancel the pending work at closing.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

22 Oct 2025, 17:15

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0125de38122f0f66bf61336158d12a1aabfe6425 - () https://git.kernel.org/stable/c/0125de38122f0f66bf61336158d12a1aabfe6425 - Patch
References () https://git.kernel.org/stable/c/11868ca21585561659c2575b0d6508ef8e9c4291 - () https://git.kernel.org/stable/c/11868ca21585561659c2575b0d6508ef8e9c4291 - Patch
References () https://git.kernel.org/stable/c/40bdb5ec957aca5c5c1924602bef6b0ab18e22d3 - () https://git.kernel.org/stable/c/40bdb5ec957aca5c5c1924602bef6b0ab18e22d3 - Patch
References () https://git.kernel.org/stable/c/517dcef4d2dda0132648f1e4c079ed17bba4d1a4 - () https://git.kernel.org/stable/c/517dcef4d2dda0132648f1e4c079ed17bba4d1a4 - Patch
References () https://git.kernel.org/stable/c/5e5fe2b6065541c6216a7a003b0cddf386be0d2d - () https://git.kernel.org/stable/c/5e5fe2b6065541c6216a7a003b0cddf386be0d2d - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ALSA: usb-audio: Cancelar trabajo pendiente al cerrar un subflujo MIDI Al cerrar un subflujo de salida MIDI USB, es posible que aún haya un trabajo pendiente, que eventualmente accedería al objeto de tiempo de ejecución rawmidi que se está liberando. Para solucionar el problema, asegúrese de cancelar el trabajo pendiente al cerrar.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-10-22 17:15


NVD link : CVE-2022-49545

Mitre link : CVE-2022-49545

CVE.ORG link : CVE-2022-49545


JSON object : View

Products Affected

linux

  • linux_kernel