cbcvebase.
CVE-2024-43818
published 2024-08-17

CVE-2024-43818: In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: Adjust error handling in case of absent codec device…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: Adjust error handling in case of absent codec device acpi_get_first_physical_node() can return NULL in several cases (no such device, ACPI table error, reference count drop to 0, etc). Existing check just emit error message, but doesn't perform return. Then this NULL pointer is passed to devm_acpi_dev_add_driver_gpios() where it is dereferenced. Adjust this error handling by adding error code return. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 02527c3f2300100a25524c8c020d98c7957e485e < 1ba9856cf7f6492b47c1edf853137f320d583db51ba9856cf7f6492b47c1edf853137f320d583db5
linuxlinux>= 02527c3f2300100a25524c8c020d98c7957e485e < 99b642dac24f6d09ba3ebf1d690be8aefff8616499b642dac24f6d09ba3ebf1d690be8aefff86164
linuxlinux>= 02527c3f2300100a25524c8c020d98c7957e485e < b1173d64edd276c957b6d09e1f971c85b38f1519b1173d64edd276c957b6d09e1f971c85b38f1519
linuxlinux>= 02527c3f2300100a25524c8c020d98c7957e485e < 5080808c3339de2220c602ab7c7fa23dc6c1a5a35080808c3339de2220c602ab7c7fa23dc6c1a5a3
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.10.3-16.10.3-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.0 < 6.1.1036.1.103
linuxlinux_kernel>= 6.2 < 6.6.446.6.44
linuxlinux_kernel>= 6.7 < 6.10.36.10.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.