CVE-2023-52806

MEDIUM

Linux Kernel < 4.14.331 - Null Pointer Dereference in ALSA HDA Stream Assignment

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix possible null-ptr-deref when assigning a stream While AudioDSP drivers assign streams exclusively of HOST or LINK type, nothing blocks a user to attempt to assign a COUPLED stream. As supplied substream instance may be a stub, what is the case when code-loading, such scenario ends with null-ptr-deref.

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (21)
Linux/Linux < 4.2
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 2527775616f3638f4fd54649eba8c7b84d5e4250
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 25354bae4fc310c3928e8a42fda2d486f67745d7
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 43b91df291c8802268ab3cfd8fccfdf135800ed4
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 4a320da7f7cbdab2098b103c47f45d5061f42edd
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 631a96e9eb4228ff75fce7e72d133ca81194797e
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 758c7733cb821041f5fd403b7b97c0b95d319323
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - 7de25112de8222fd20564769e6c99dc9f9738a0b
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - f93dc90c2e8ed664985e366aa6459ac83cdab236
Linux/Linux 14752412721c61d9ac1e8d8fb51d7148cb15f85b - fe7c1a0c2b25c82807cb46fc3aadbf2664a682b0
... and 11 more
Published May 21, 2024
Tracked Since Feb 18, 2026