cbcvebase.
CVE-2024-56657
published 2024-12-27

CVE-2024-56657: In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Avoid WARN() for symlink errors Using WARN() for showing the error of symlink creations don't give more information than telling that something goes wrong, since the usual code path is a lregister callback from each control element creation. More badly, the use of WARN() rather confuses fuzzer as if it were serious issues. This patch downgrades the warning messages to use the normal dev_err() instead of WARN(). For making it clearer, add the function name to the prefix, too.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.6-1 (forky)linux 6.12.6-1 (forky)
linuxlinux
linuxlinux>= a135dfb5de1501327895729b4f513370d2555b4d < 4e5a92a7223c83c1f5f2db6cd010ac93479489724e5a92a7223c83c1f5f2db6cd010ac9347948972
linuxlinux>= a135dfb5de1501327895729b4f513370d2555b4d < 365ee29e559269cbb2108c4cc05dd8e262b4e84e365ee29e559269cbb2108c4cc05dd8e262b4e84e
linuxlinux>= a135dfb5de1501327895729b4f513370d2555b4d < d5a1ca7b59804d6779644001a878ed925a4688cad5a1ca7b59804d6779644001a878ed925a4688ca
linuxlinux>= a135dfb5de1501327895729b4f513370d2555b4d < 36c0764474b637bbee498806485bed524cad486b36c0764474b637bbee498806485bed524cad486b
linuxlinux>= a135dfb5de1501327895729b4f513370d2555b4d < b2e538a9827dd04ab5273bf4be8eb2edb84357b0b2e538a9827dd04ab5273bf4be8eb2edb84357b0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.13 < 6.6.676.6.67
linuxlinux_kernel>= 6.7 < 6.12.66.12.6
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.173.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure-5.15
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15
ubuntulinux-fips

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.