CVE-2024-41037: ASoC: SOF: Intel: hda: fix null deref on system suspend entry
Published Jul 29, 2024
·Updated
ASoC: SOF: Intel: hda: fix null deref on system suspend entry
Affected Software
5 affected componentsFixes available
Linux Linux kernel>=6.4<6.6.41
Linux Linux kernel>=6.7<6.9.10
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Microsoft azl3 kernel 6.6.43.1-7
Microsoft azl3 kernel 6.6.35.1-5
Remediation
Event History
Jul 29, 2024
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Aug 16, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Dec 15, 2024
Data Sourced
via Ubuntu·12:30 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-41037?
CVE-2024-41037 is classified with a moderate severity level due to the potential for a null dereference when suspending the system.
2
How do I fix CVE-2024-41037?
To resolve CVE-2024-41037, update to a fixed version of the Linux kernel, specifically any version higher than the vulnerable ones listed.
3
What systems are affected by CVE-2024-41037?
CVE-2024-41037 affects Linux kernel versions between 6.4 and 6.6.41, as well as versions between 6.7 and 6.9.10.
4
How does CVE-2024-41037 impact system performance?
CVE-2024-41037 can lead to system instability and crashes during suspend operations when an active audio stream is present.
5
Is there a specific Linux distribution that is affected by CVE-2024-41037?
Yes, Debian-based distributions running vulnerable versions of the Linux kernel are affected by CVE-2024-41037.