cbcvebase.
CVE-2024-41037
published 2024-07-29

CVE-2024-41037: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: fix null deref on system suspend entry When system enters suspend…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: fix null deref on system suspend entry When system enters suspend with an active stream, SOF core calls hw_params_upon_resume(). On Intel platforms with HDA DMA used to manage the link DMA, this leads to call chain of hda_dsp_set_hw_params_upon_resume() -> hda_dsp_dais_suspend() -> hda_dai_suspend() -> hda_ipc4_post_trigger() A bug is hit in hda_dai_suspend() as hda_link_dma_cleanup() is run first, which clears hext_stream->link_substream, and then hda_ipc4_post_trigger() is called with a NULL snd_pcm_substream pointer.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.10-1 (forky)linux 6.9.10-1 (forky)
linuxlinux
linuxlinux>= 2b009fa0823c1510700fd17a0780ddd06a460fb4 < 8246bbf818ed7b8d5afc92b951e6d562b45c24508246bbf818ed7b8d5afc92b951e6d562b45c2450
linuxlinux>= 2b009fa0823c1510700fd17a0780ddd06a460fb4 < 993af0f2d9f24e3c18a445ae22b34190d1fcad61993af0f2d9f24e3c18a445ae22b34190d1fcad61
linuxlinux>= 2b009fa0823c1510700fd17a0780ddd06a460fb4 < 9065693dcc13f287b9e4991f43aee70cf5538fdd9065693dcc13f287b9e4991f43aee70cf5538fdd
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 6.4 < 6.6.416.6.41
linuxlinux_kernel>= 6.7 < 6.9.106.9.10
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.