cbcvebase.
CVE-2024-38551
published 2024-06-19

CVE-2024-38551: In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Assign dummy when codec not specified for a DAI link MediaTek sound card…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Assign dummy when codec not specified for a DAI link MediaTek sound card drivers are checking whether a DAI link is present and used on a board to assign the correct parameters and this is done by checking the codec DAI names at probe time. If no real codec is present, assign the dummy codec to the DAI link to avoid NULL pointer during string comparison.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.12-1 (forky)linux 6.8.12-1 (forky)
linuxlinux
linuxlinux>= 4302187d955f166c03b4fa7c993b89ffbabfca4e < 87b8dca6e06f9b1681bc52bf7bfa85c663a1115887b8dca6e06f9b1681bc52bf7bfa85c663a11158
linuxlinux>= 4302187d955f166c03b4fa7c993b89ffbabfca4e < cbbcabc7f0979f6542372cf88d7a9da7143a4226cbbcabc7f0979f6542372cf88d7a9da7143a4226
linuxlinux>= 4302187d955f166c03b4fa7c993b89ffbabfca4e < 0c052b1c11d8119f3048b1f7b3c39a90500cacf90c052b1c11d8119f3048b1f7b3c39a90500cacf9
linuxlinux>= 4302187d955f166c03b4fa7c993b89ffbabfca4e < 5f39231888c63f0a7708abc86b51b847476379d85f39231888c63f0a7708abc86b51b847476379d8
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.3 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.