cbcvebase.
CVE-2024-44954
published 2024-09-04

CVE-2024-44954: In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: Fix racy access to midibuf There can be concurrent accesses to line6 midibuf…

PriorityP417medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: Fix racy access to midibuf There can be concurrent accesses to line6 midibuf from both the URB completion callback and the rawmidi API access. This could be a cause of KMSAN warning triggered by syzkaller below (so put as reported-by here). This patch protects the midibuf call of the former code path with a spinlock for avoiding the possible races.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < 643293b68fbb6c03f5e907736498da17d43f0d81643293b68fbb6c03f5e907736498da17d43f0d81
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < 40f3d5cb0e0cbf7fa697913a27d5d361373bdcf540f3d5cb0e0cbf7fa697913a27d5d361373bdcf5
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < e7e7d2b180d8f297cea6db43ea72402fd33e1a29e7e7d2b180d8f297cea6db43ea72402fd33e1a29
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < a54da4b787dcac60b598da69c9c0072812b8282da54da4b787dcac60b598da69c9c0072812b8282d
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < c80f454a805443c274394b1db0d1ebf477abd94ec80f454a805443c274394b1db0d1ebf477abd94e
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < 535df7f896a568a8a1564114eaea49d002cb1747535df7f896a568a8a1564114eaea49d002cb1747
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < 51d87f11dd199bbc6a85982b088ff27bde53b48a51d87f11dd199bbc6a85982b088ff27bde53b48a
linuxlinux>= 705ececd1c60d0f5d6ef2a719008847883516970 < 15b7a03205b31bc5623378c190d22b7ff60026f115b7a03205b31bc5623378c190d22b7ff60026f1
linuxlinux_kernel< 4.19.3204.19.320
linuxlinux_kernel< 5.4.2825.4.282
linuxlinux_kernel< 5.15.1655.15.165
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.16 < 6.1.1056.1.105
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.