CVE-2024-42097
MEDIUMLinux Kernel - Unauthenticated Denial of Service via ALSA Emux Patch IOCTL Data Validation
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ALSA: emux: improve patch ioctl data validation In load_data(), make the validation of and skipping over the main info block match that in load_guspatch(). In load_guspatch(), add checking that the specified patch length matches the actually supplied data, like load_data() already did.
References (10)
Core 10
Core References
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-265688.html
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
13.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (26)
linux/Kernel
2.6.12 - 4.19.317linux
linux/Kernel
4.20.0 - 5.4.279linux
linux/Kernel
5.11.0 - 5.15.162linux
linux/Kernel
5.16.0 - 6.1.97linux
linux/Kernel
5.5.0 - 5.10.221linux
linux/Kernel
6.2.0 - 6.6.37linux
linux/Kernel
6.7.0 - 6.9.8linux
Linux/Linux
< 2.6.12
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 40d7def67841343c10f8642a41031fecbb248bab
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 79d9a000f0220cdaba1682d2a23c0d0c61d620a3
... and 16 more
Published
Jul 29, 2024
Tracked Since
Feb 18, 2026