Linux Kernel Vulnerability in Greybus Audio Helper Code
CVE-2022-50400
What is CVE-2022-50400?
A flaw in the greybus audio_helper code within the Linux kernel allows for potential memory leaks and the unintended removal of debugfs entries. This occurs due to improper handling of a debugfs file not created by the audio_helper but by the sound core. The issue arises from faulty debugfs logic, which, if executed, may lead to a systemic disruption by affecting all debugfs entries. To rectify this, all debuggable features associated with the audio_helper should be eliminated, ensuring greater stability and system integrity. A thorough revisit of the debugfs_lookup() functionality is suggested for any necessary future implementations.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4dab0d27a4211a27135a6899d6c737e6e0759a11
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5699afbff1fa2972722e863906c0320d55dd4d58