CVE-2024-57893Race Condition in Linux

Severity
6.3MEDIUMNVD
OSV7.8OSV7.1OSV6.2OSV5.5
EPSS
0.0%
top 97.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 29

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix races at processing SysEx messages OSS sequencer handles the SysEx messages split in 6 bytes packets, and ALSA sequencer OSS layer tries to combine those. It stores the data in the internal buffer and this access is racy as of now, which may lead to the out-of-bounds access. As a temporary band-aid fix, introduce a mutex for serializing the process of the SysEx message packets.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.0 | Impact: 5.2

Affected Packages6 packages

NVDlinux/linux_kernel6.26.6.70+3
Debianlinux/linux_kernel< 6.1.124-1+2
Ubuntulinux/linux_kernel< 6.8.0-60.63
CVEListV5linux/linux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2cff1de87ed14fc0f2332213d2367100e7ad0753a+4
debiandebian/linux< linux 6.1.124-1 (bookworm)

Patches

🔴Vulnerability Details

18
OSV
linux-oracle-6.8 vulnerabilities2025-05-29
OSV
linux-hwe-6.8 vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-26
OSV
linux-azure-nvidia vulnerabilities2025-05-20
OSV
linux-raspi-realtime vulnerabilities2025-05-20

📋Vendor Advisories

18
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-05-29
Ubuntu
Linux kernel (HWE) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-26
Ubuntu
Linux kernel vulnerabilities2025-05-20
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2025-05-20