CVE-2024-42278: ASoC: TAS2781: Fix tasdev_load_calibrated_data()
Published Aug 17, 2024
·Updated
In the Linux kernel, the following vulnerability has been resolved:
ASoC: TAS2781: Fix tasdevloadcalibrateddata()
This function has a reversed if statement so it's either a no-op or it leads to a NULL dereference.
Affected Software
4 affected componentsFixes available
Linux Linux kernel>=6.6.33<6.6.44
Linux Linux kernel>=6.9.4<6.10
Linux Linux kernel>=6.10<6.10.3
debian/linux
5.10.223-15.10.234-16.1.129-16.1.133-16.12.22-1
Remediation
Event History
Aug 17, 2024
CVE Published
via MITRE·09:08 AM
Data Sourced
via MITRE·09:08 AM
Description
Jan 9, 2025
Data Sourced
via Ubuntu·06:28 PM
RemedyDescriptionSeverityAffected Software
Apr 23, 2025
Data Sourced
via Debian·07:36 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42278?
CVE-2024-42278 is considered a moderate severity vulnerability due to potential NULL dereference issues.
2
How do I fix CVE-2024-42278?
To fix CVE-2024-42278, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
3
Which versions of the Linux kernel are affected by CVE-2024-42278?
CVE-2024-42278 affects Linux kernel versions between 6.6.33 to 6.6.44, 6.9.4 to 6.10, and up to 6.10.3.
4
What components are impacted by CVE-2024-42278?
CVE-2024-42278 impacts the ASoC TAS2781 component within the Linux kernel.
5
Is there a workaround for CVE-2024-42278?
Currently, the recommended action for CVE-2024-42278 is to apply the available updates as no specific workaround is suggested.