CVE-2023-52697
HIGHLinux Kernel 6.5-6.6.13 - Use-After-Free in ASoC Intel SOF SDW RT SDCA Jack Exit
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name. For example, rt712 and rt713 both use "rt712-sdca-aif1" and sof_sdw_rt_sdca_jack_exit(). As a result, sof_sdw_rt_sdca_jack_exit() will be called twice by mc_dailink_exit_loop(). Set ctx->headset_codec_dev = NULL; after put_device(ctx->headset_codec_dev); to avoid ctx->headset_codec_dev being put twice.
References (3)
Core 3
Scores
CVSS v3
7.1
EPSS
0.0021
EPSS Percentile
11.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (11)
linux/Kernel
6.5.0 - 6.6.14linux
linux/Kernel
6.7.0 - 6.7.2linux
Linux/Linux
< 6.5
Linux/Linux
5360c67046385f90406ec17e367ba9aeb42d5459 - 582231a8c4f73ac153493687ecc1bed853e9c9ef
Linux/Linux
5360c67046385f90406ec17e367ba9aeb42d5459 - a410d58117d6da4b7d41f3c91365f191d006bc3d
Linux/Linux
5360c67046385f90406ec17e367ba9aeb42d5459 - e38e252dbceeef7d2f848017132efd68e9ae1416
Linux/Linux
6.5
Linux/Linux
6.6.14 - 6.6.*
Linux/Linux
6.7.2 - 6.7.*
Linux/Linux
6.8
... and 1 more
Published
May 17, 2024
Tracked Since
Feb 18, 2026