CVE-2024-50105
Last modified
CVE-2024-50105 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: sc7280: Fix missing Soundwire runtime stream alloc Commit 15c7fab0e047 ("ASoC: qcom: Move Soundwire runtime stream alloc to soundcards") moved the allocation of Soundwire stream runtime from the Qualcomm Soundwire driver to each individual machine sound card driver, except that it forgot to update SC7280 card. Just like for other Qualcomm sound cards using Soundwire, the card driver should allocate and release the runtime. Otherwise sound playback will result in a NULL pointer dereference or other effect of uninitialized memory accesses (which was confirmed on SDM845 having similar issue).. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: sc7280: Fix missing Soundwire runtime stream alloc Commit 15c7fab0e047 ("ASoC: qcom: Move Soundwire runtime stream alloc to soundcards") moved the allocation of Soundwire stream runtime from the Qualcomm Soundwire driver to each individual machine sound card driver, except that it forgot to update SC7280 card. Just like for other Qualcomm sound cards using Soundwire, the card driver should allocate and release the runtime. Otherwise sound playback will result in a NULL pointer dereference or other effect of uninitialized memory accesses (which was confirmed on SDM845 having similar issue).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 6.8, < 6.11.6 | — |
| Linux | Linux Kernel | 6.12 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-50105?
How severe is CVE-2024-50105?
How do I fix CVE-2024-50105?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5010In WhatsUp Gold versions released before 2023.1.3, a vulnera…7.5
- CVE-2024-50100In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50101In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50102In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50103In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50104In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50106In the Linux kernel, the following vulnerability has been re…7
- CVE-2024-50107In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50108In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-50109In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-5011In WhatsUp Gold versions released before 2023.1.3, an uncont…7.5
- CVE-2024-50110In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2024-50105?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
