Description
An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses kstrndup instead of kmemdup_nul, which allows attackers to have an unspecified impact via unknown vectors. NOTE: The vendor disputes this issues as not being a vulnerability because switching to kmemdup_nul() would only fix a security issue if the source string wasn't NUL-terminated, which is not the case
References (6)
Core 6
Core References
Mailing List, Patch, Third Party Advisory x_refsource_misc
https://lkml.org/lkml/2019/5/29/705
Mailing List, Patch, Vendor Advisory x_refsource_misc
https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git/commit/?h=for-5.3&id=a54988113985ca22e414e132054f234fc8a92604
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J36BIJTKEPUOZKJNHQBUZA47RQONUKOI/
Issue Tracking x_refsource_misc
https://bugzilla.suse.com/show_bug.cgi?id=1136963#c1
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K13523672
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K13523672?utm_source=f5support&%3Butm_medium=RSS
Scores
CVSS v3
7.8
EPSS
0.0044
EPSS Percentile
36.5%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (1)
linux/linux_kernel
< 5.1.5
Published
May 30, 2019
Tracked Since
Feb 18, 2026