cbcvebase.
CVE-2024-57880
published 2025-01-11

CVE-2024-57880: In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array The code uses the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array The code uses the initialised member of the asoc_sdw_dailink struct to determine if a member of the array is in use. However in the case the array is completely full this will lead to an access 1 past the end of the array, expand the array by one entry to include a space for a terminator.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.6-1 (forky)linux 6.12.6-1 (forky)
linuxlinux
linuxlinux>= 27fd36aefa0013bea1cf6948e2e825e9b8cff97a < b21a849764a4111b0bc14a5ffe987a0582419de2b21a849764a4111b0bc14a5ffe987a0582419de2
linuxlinux>= 27fd36aefa0013bea1cf6948e2e825e9b8cff97a < 255cc582e6e16191a20d54bcdbca6c91d3e90c5e255cc582e6e16191a20d54bcdbca6c91d3e90c5e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 6.10 < 6.12.66.12.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.