cbcvebase.
CVE-2023-52674
published 2024-05-17

CVE-2023-52674: In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put() Ensure the value passed to…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put() Ensure the value passed to scarlett2_mixer_ctl_put() is between 0 and SCARLETT2_MIXER_MAX_VALUE so we don't attempt to access outside scarlett2_mixer_values[].

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 9e4d5c1be21f0c00e747e92186784f3298309b3e < e517645ead5ea22c69d2a44694baa23fe1ce7c2be517645ead5ea22c69d2a44694baa23fe1ce7c2b
linuxlinux>= 9e4d5c1be21f0c00e747e92186784f3298309b3e < d8d8897d65061cbe36bf2909057338303a904810d8d8897d65061cbe36bf2909057338303a904810
linuxlinux>= 9e4d5c1be21f0c00e747e92186784f3298309b3e < 03035872e17897ba89866940bbc9cefca601e57203035872e17897ba89866940bbc9cefca601e572
linuxlinux>= 9e4d5c1be21f0c00e747e92186784f3298309b3e < ad945ea8d47dd4454c271510bea24850119847c2ad945ea8d47dd4454c271510bea24850119847c2
linuxlinux>= 9e4d5c1be21f0c00e747e92186784f3298309b3e < 04f8f053252b86c7583895c962d66747ecdc61b704f8f053252b86c7583895c962d66747ecdc61b7
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.4 < 5.15.1485.15.148
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.