CVE-2022-49772
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2025
Last modified:
02/05/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ALSA: usb-audio: Drop snd_BUG_ON() from snd_usbmidi_output_open()<br />
<br />
snd_usbmidi_output_open() has a check of the NULL port with<br />
snd_BUG_ON(). snd_BUG_ON() was used as this shouldn&#39;t have happened,<br />
but in reality, the NULL port may be seen when the device gives an<br />
invalid endpoint setup at the descriptor, hence the driver skips the<br />
allocation. That is, the check itself is valid and snd_BUG_ON()<br />
should be dropped from there. Otherwise it&#39;s confusing as if it were<br />
a real bug, as recently syzbot stumbled on it.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/00f5f1bbf815a39e9eecb468d12ca55d3360eb10
- https://git.kernel.org/stable/c/02b94885b2fdf1808b1874e009bfb90753f8f4db
- https://git.kernel.org/stable/c/368a01e5064c13946d032ab1d65ba95020a39cc5
- https://git.kernel.org/stable/c/872c9314769e89d8bda74ff3ac584756a45ee752
- https://git.kernel.org/stable/c/a80369c8ca50bc885d14386087a834659ec54a54
- https://git.kernel.org/stable/c/ad72c3c3f6eb81d2cb189ec71e888316adada5df
- https://git.kernel.org/stable/c/c43991065f36f7628cd124e037b8750c4617a7a7
- https://git.kernel.org/stable/c/e7dc436aea80308a9268e6d2d85f910ff107de9b