cbcvebase.
CVE-2023-54072
published 2025-12-24

CVE-2023-54072: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory…

PriorityP423medium6.3
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory allocation helpers have a sanity check against too many buffer allocations. However, the check is performed without a proper lock and the allocation isn't serialized; this allows user to allocate more memories than predefined max size. Practically seen, this isn't really a big problem, as it's more or less some "soft limit" as a sanity check, and it's not possible to allocate unlimitedly. But it's still better to address this for more consistent behavior. The patch covers the size check in do_alloc_pages() with the card->memory_mutex, and increases the allocated size there for preventing the further overflow. When the actual allocation fails, the size is decreased accordingly.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 95b30a4312545f2dde9db12bf6a425f35d5a0d77 < 7e1d1456c8db9949459c5a24e8845cfe92430b0f7e1d1456c8db9949459c5a24e8845cfe92430b0f
linuxlinux>= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 7e11c58b2620a22c67a5ae28d64ce383890ee9f47e11c58b2620a22c67a5ae28d64ce383890ee9f4
linuxlinux>= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < a0ab49e7a758b488b2090171a75d50735c0876f6a0ab49e7a758b488b2090171a75d50735c0876f6
linuxlinux>= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 3eb4e47a94e3f76521d7d344696db61e6a9619c73eb4e47a94e3f76521d7d344696db61e6a9619c7
linuxlinux>= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 773ccad902f67583a58b5650a2f8d8daf2e76fac773ccad902f67583a58b5650a2f8d8daf2e76fac
linuxlinux>= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < bd55842ed998a622ba6611fe59b3358c9f76773dbd55842ed998a622ba6611fe59b3358c9f76773d
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 5.11.0 < 5.15.1295.15.129
linuxlinux_kernel>= 5.16.0 < 6.1.396.1.39
linuxlinux_kernel>= 5.6.0 < 5.10.1935.10.193
linuxlinux_kernel>= 6.2.0 < 6.4.46.4.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.