cbcvebase.
CVE-2023-52806
published 2024-05-21

CVE-2023-52806: In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix possible null-ptr-deref when assigning a stream While AudioDSP drivers…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix possible null-ptr-deref when assigning a stream While AudioDSP drivers assign streams exclusively of HOST or LINK type, nothing blocks a user to attempt to assign a COUPLED stream. As supplied substream instance may be a stub, what is the case when code-loading, such scenario ends with null-ptr-deref.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 7de25112de8222fd20564769e6c99dc9f9738a0b7de25112de8222fd20564769e6c99dc9f9738a0b
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 758c7733cb821041f5fd403b7b97c0b95d319323758c7733cb821041f5fd403b7b97c0b95d319323
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 2527775616f3638f4fd54649eba8c7b84d5e42502527775616f3638f4fd54649eba8c7b84d5e4250
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 25354bae4fc310c3928e8a42fda2d486f67745d725354bae4fc310c3928e8a42fda2d486f67745d7
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 631a96e9eb4228ff75fce7e72d133ca81194797e631a96e9eb4228ff75fce7e72d133ca81194797e
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 43b91df291c8802268ab3cfd8fccfdf135800ed443b91df291c8802268ab3cfd8fccfdf135800ed4
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < fe7c1a0c2b25c82807cb46fc3aadbf2664a682b0fe7c1a0c2b25c82807cb46fc3aadbf2664a682b0
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < 4a320da7f7cbdab2098b103c47f45d5061f42edd4a320da7f7cbdab2098b103c47f45d5061f42edd
linuxlinux>= 14752412721c61d9ac1e8d8fb51d7148cb15f85b < f93dc90c2e8ed664985e366aa6459ac83cdab236f93dc90c2e8ed664985e366aa6459ac83cdab236
linuxlinux_kernel< 4.14.3314.14.331
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 0 < 4.15.0-228.2404.15.0-228.240
linuxlinux_kernel>= 4.15 < 4.19.3004.19.300
linuxlinux_kernel>= 4.20 < 5.4.2625.4.262
linuxlinux_kernel>= 5.11 < 5.15.1405.15.140
linuxlinux_kernel>= 5.16 < 6.1.646.1.64
linuxlinux_kernel>= 5.5 < 5.10.2025.10.202
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.