{"schema_version":"1.9.0","id":"CVE-2022-49498","published":"2025-02-26T02:13:32.895Z","modified":"2026-08-12T03:51:35.525440245Z","related":["SUSE-SU-2025:1027-1","SUSE-SU-2025:1176-1","SUSE-SU-2025:1183-1","SUSE-SU-2025:1194-1","SUSE-SU-2025:1241-1","SUSE-SU-2025:1263-1"],"summary":"ALSA: pcm: Check for null pointer of pointer substream before dereferencing it","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Check for null pointer of pointer substream before dereferencing it\n\nPointer substream is being dereferenced on the assignment of pointer card\nbefore substream is being null checked with the macro PCM_RUNTIME_CHECK.\nAlthough PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the\nthe pointer check before card is assigned.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"95b30a4312545f2dde9db12bf6a425f35d5a0d77"},{"fixed":"b2421a196cb0911ea95aec1050a0b830464c8fa6"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"d4cfb30fce03093ad944e0b44bd8f40bdad5330e"},{"fixed":"f2c68c52898f623fe84518da4606538d193b0cca"},{"fixed":"7784d22f81a29df2ec57ca90d54f93a35cbcd1a2"},{"fixed":"1f2e28857be1e5c7db39bbc221332215fc5467e3"},{"fixed":"b41ef7ad9238c22aa2e142f5ce4ce1a1a0d48123"},{"fixed":"011b559be832194f992f73d6c0d5485f5925a10b"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49498.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6.0"},{"fixed":"5.10.121"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.46"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.17.14"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.18.0"},{"fixed":"5.18.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49498.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/011b559be832194f992f73d6c0d5485f5925a10b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1f2e28857be1e5c7db39bbc221332215fc5467e3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7784d22f81a29df2ec57ca90d54f93a35cbcd1a2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b2421a196cb0911ea95aec1050a0b830464c8fa6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b41ef7ad9238c22aa2e142f5ce4ce1a1a0d48123"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f2c68c52898f623fe84518da4606538d193b0cca"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49498.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-49498"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49498.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}