CVE-2022-48992: ASoC: soc-pcm: Add NULL check in BE reparenting
In the Linux kernel, the following vulnerability has been resolved:
ASoC: soc-pcm: Add NULL check in BE reparenting
Add NULL check in dpcm_be_reparent API, to handle
kernel NULL pointer dereference error.
The issue occurred in fuzzing test.
Security readout for executives and security teams
Plain-English summary
CVE-2022-48992 is a Linux kernel bug in the ASoC audio path where missing NULL handling could cause a kernel crash. The issue was found by fuzzing. The public bundle does not provide CVSS, exploitability, or business impact detail, so urgency should be based on kernel exposure and vendor patch availability.
Executive priority
Track this as a patch-management item, not an emergency based on current evidence. Escalate priority for appliances, embedded Linux, or fleets with exposed local users where kernel crashes create service disruption or reliability risk.
Technical view
The resolved issue adds a NULL check in dpcm_be_reparent within ASoC soc-pcm to prevent a kernel NULL pointer dereference during BE reparenting. References point to Linux stable commits across maintained branches. The source bundle names Linux kernel versions as affected but does not describe a privilege boundary, reachable interface, or exploit chain.
Likely exposure
Exposure is most plausible on Linux systems running affected kernels where the ASoC/DPCM audio code is present and reachable. Embedded or SoC-based Linux devices may deserve closer review. The bundle does not identify distributions, hardware models, containers, or cloud platforms as affected.
Exploitation context
The source states the issue occurred during fuzzing. There is no KEV listing and no cited source in the bundle claiming active exploitation, public exploitation, or weaponized use. Treat exploitation status as unconfirmed rather than active.
Researcher notes
Evidence is limited to the CVE description and Linux stable commit references. No CVSS, CWE, exploit status, attack vector, or precise distro mapping is provided. Validation should focus on commit ancestry, vendor backports, kernel configuration, and whether ASoC/DPCM paths are relevant to the asset.
Mitigation direction
Update affected Linux kernels through the normal vendor or kernel stable channel.
Confirm vendor packages include one of the referenced stable fixes or an equivalent backport.
Prioritize systems with ASoC/DPCM audio functionality enabled or exposed to untrusted local users.
Monitor Linux distribution advisories for package-specific affected and fixed version mapping.
If no fix is available, follow vendor guidance rather than applying unsupported changes.
Validation and detection
Inventory Linux kernel versions and compare them with vendor affected and fixed package data.
Check kernel source or package changelog for the referenced stable fix or equivalent backport.
Review whether ASoC and DPCM audio support are enabled in relevant kernel builds.
Confirm patched systems reboot into the updated kernel, not only install the package.
Document any unsupported or end-of-life kernels requiring replacement or isolation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-48992 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.