CVE-2024-38551

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Assign dummy when codec not specified for a DAI link MediaTek sound card drivers are checking whether a DAI link is present and used on a board to assign the correct parameters and this is done by checking the codec DAI names at probe time. If no real codec is present, assign the dummy codec to the DAI link to avoid NULL pointer during string comparison.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

27 Aug 2024, 19:54

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
References () https://git.kernel.org/stable/c/0c052b1c11d8119f3048b1f7b3c39a90500cacf9 - () https://git.kernel.org/stable/c/0c052b1c11d8119f3048b1f7b3c39a90500cacf9 - Patch
References () https://git.kernel.org/stable/c/5f39231888c63f0a7708abc86b51b847476379d8 - () https://git.kernel.org/stable/c/5f39231888c63f0a7708abc86b51b847476379d8 - Patch
References () https://git.kernel.org/stable/c/87b8dca6e06f9b1681bc52bf7bfa85c663a11158 - () https://git.kernel.org/stable/c/87b8dca6e06f9b1681bc52bf7bfa85c663a11158 - Patch
References () https://git.kernel.org/stable/c/cbbcabc7f0979f6542372cf88d7a9da7143a4226 - () https://git.kernel.org/stable/c/cbbcabc7f0979f6542372cf88d7a9da7143a4226 - Patch

20 Jun 2024, 12:44

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ASoC: mediatek: Asignar dummy cuando el códec no está especificado para un enlace DAI Los controladores de la tarjeta de sonido MediaTek están comprobando si hay un enlace DAI presente y utilizado en una placa para asignar los parámetros correctos y esto se realiza comprobando los nombres DAI del códec en el momento de la sonda. Si no hay ningún códec real, asigne el códec ficticio al enlace DAI para evitar el puntero NULL durante la comparación de cadenas.

19 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-19 14:15

Updated : 2024-08-27 19:54


NVD link : CVE-2024-38551

Mitre link : CVE-2024-38551

CVE.ORG link : CVE-2024-38551


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference