CVE-2022-48702 is an out-of-bounds access vulnerability in the Linux kernel's ALSA emu10k1 sound driver. Specifically, the snd_emu10k1_pcm_channel_alloc() function can attempt to access memory beyond the allocated array for sound voices when the voice allocator wraps around and a high number of voices are requested. This vulnerability affects Linux kernel versions and can be triggered by local users, for example, by using 'aplay' with 16 channels. Rated with a CVSS score of 7.8 (HIGH), this vulnerability has a local attack vector and low attack complexity, requiring low privileges and no user interaction. Successful exploitation could lead to high confidentiality, integrity, and availability impacts, potentially causing system crashes or arbitrary code execution. There is no evidence of active exploitation, nor are there known public exploit codes (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.9.328CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.293CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.258CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.213CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.143CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.