CVE-2024-50160

MEDIUM

Linux Kernel 5.15-5.15.169 5.16-6.1.114 6.2-6.6.58 6.7-6.11.5 - NULL Pointer Dereference in ALSA CS8409 Fixup

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs8409: Fix possible NULL dereference If snd_hda_gen_add_kctl fails to allocate memory and returns NULL, then NULL pointer dereference will occur in the next line. Since dolphin_fixups function is a hda_fixup function which is not supposed to return any errors, add simple check before dereference, ignore the fail. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 11.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (18)
linux/Kernel 5.15.0 - 5.15.170linux
linux/Kernel 5.16.0 - 6.1.115linux
linux/Kernel 6.2.0 - 6.6.59linux
linux/Kernel 6.7.0 - 6.11.6linux
Linux/Linux < 5.15
Linux/Linux 20e507724113300794f16884e7e7507d9b4dec68 - 21dc97d5086fdabbe278786bb0a03cbf2e26c793
Linux/Linux 20e507724113300794f16884e7e7507d9b4dec68 - 4e19aca8db696b6ba4dd8c73657405e15c695f14
Linux/Linux 20e507724113300794f16884e7e7507d9b4dec68 - 8971fd61210d75fd2af225621cd2fcc87eb1847c
Linux/Linux 20e507724113300794f16884e7e7507d9b4dec68 - a5dd71a8b849626f42d08a5e73d382f2016fc7bc
Linux/Linux 20e507724113300794f16884e7e7507d9b4dec68 - c9bd4a82b4ed32c6d1c90500a52063e6e341517f
... and 8 more
Published Nov 07, 2024
Tracked Since Feb 18, 2026