CVE-2024-42074: ASoC: amd: acp: add a null check for chip_pdev structure
Published Jul 29, 2024
·Updated
ASoC: amd: acp: add a null check for chippdev structure
Affected Software
9 affected componentsFixes available
Linux Linux kernel<6.6
Linux Linux kernel>=6.6.1<6.6.37
Linux Linux kernel>=6.7<6.9.8
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Microsoft azl3 kernel 6.6.35.1-5
Microsoft cbl2 kernel 5.15.180.1-1
Microsoft azl3 kernel 6.6.43.1-7
Microsoft cbl2 kernel 5.15.180.1-1
Microsoft cbl2 kernel 5.15.162.2-1
Remediation
Event History
Jul 29, 2024
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
Description
Aug 10, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Dec 15, 2024
Data Sourced
via Ubuntu·12:32 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42074?
CVE-2024-42074 has a medium severity level as it involves a NULL pointer dereference in the Linux kernel.
2
How do I fix CVE-2024-42074?
To fix CVE-2024-42074, update your Linux kernel to a version where the vulnerability has been patched, such as 5.10.223-1 or newer.
3
Which versions of Linux kernel are affected by CVE-2024-42074?
CVE-2024-42074 affects Linux kernel versions up to 6.6 and versions between 6.6.1 and 6.6.37 as well as 6.7 to 6.9.8.
4
What is the impact of CVE-2024-42074?
The impact of CVE-2024-42074 may result in a denial of service due to a NULL pointer dereference during the sound card resume process.
5
Is CVE-2024-42074 likely to be exploited?
While CVE-2024-42074 has potential for exploitation, its actual risk depends on the specific deployment and usage of the affected Linux kernel.