CVE-2022-3303

Updated: 2025-08-20 00:16:52.330777

Description:

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 4.7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 4.7 MEDIUM Ignored 2023-11-21 04:12:07 This flaw is a local-only, high-complexity race in the legacy OSS audio path (SNDCTL_DSP_SYNC) that ...
CentOS 6 ELS kernel 2.6.32 4.7 MEDIUM Ignored 2022-09-30 08:02:26 Ignored due to low severity
CentOS 7 ELS kernel 3.10.0 4.7 MEDIUM Ignored 2023-09-19 05:07:34 Ignored due to low severity
CentOS 8.4 ELS kernel 4.18.0 4.7 MEDIUM Ignored 2022-09-30 08:02:25 Ignored due to low severity
CentOS 8.5 ELS kernel 4.18.0 4.7 MEDIUM Ignored 2022-09-30 08:02:25 Ignored due to low severity
CloudLinux 6 ELS kernel 2.6.32 4.7 MEDIUM Ignored 2022-09-30 08:02:26 Ignored due to low severity
Oracle Linux 6 ELS kernel 2.6.32 4.7 MEDIUM Ignored 2022-09-30 08:02:25 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 4.7 MEDIUM Released CLSA-2023:1689788960 2023-07-19 14:09:51
Ubuntu 16.04 ELS linux 4.4.0 4.7 MEDIUM Released CLSA-2023:1682604577 2023-04-27 11:09:26
Ubuntu 18.04 ELS linux 4.15.0 4.7 MEDIUM Released CLSA-2023:1693429208 2023-08-30 17:10:05