CVE-2024-39473: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension
If a process module does not have base config extension then the same format applies to all of it's inputs and the process->baseconfigext is NULL, causing NULL dereference when specifically crafted topology and sequences used.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension
The Linux kernel CVE team has assigned CVE-2024-39473 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024070516-CVE-2024-39473-d28c@gregkh/T
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39473?
CVE-2024-39473 is classified as a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-39473?
To fix CVE-2024-39473, update your Linux kernel to versions 6.6.34, 6.9.5, or 6.10, or the specific Debian kernel versions mentioned.
Which systems are affected by CVE-2024-39473?
CVE-2024-39473 affects various versions of the Linux kernel up to 6.4 and all versions below the fixed versions.
Is CVE-2024-39473 related to any specific Linux distributions?
CVE-2024-39473 impacts Red Hat and Debian distributions that use the affected versions of the Linux kernel.
What are the implications of CVE-2024-39473?
The implications of CVE-2024-39473 may include improper processing of audio inputs which could lead to system instability.