CVE-2024-44954: ALSA: line6: Fix racy access to midibuf

Published Sep 4, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ALSA: line6: Fix racy access to midibuf

There can be concurrent accesses to line6 midibuf from both the URB completion callback and the rawmidi API access. This could be a cause of KMSAN warning triggered by syzkaller below (so put as reported-by here).

This patch protects the midibuf call of the former code path with a spinlock for avoiding the possible races.

Affected Software

11 affected componentsFixes available
Linux Linux kernel<4.19.320
Linux Linux kernel>4.20<5.4.282
Linux Linux kernel>=5.5<5.10.224
Linux Linux kernel>5.11<5.15.165
Linux Linux kernel>=5.16<6.1.105
Linux Linux kernel>=6.2<6.6.46
Linux Linux kernel>=6.7<6.10.5
Linux Linux kernel=6.11-rc1
Linux Linux kernel=6.11-rc2
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.129-1~deb11u1

Event History

Sep 4, 2024
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 5, 2025
Data Sourced
via Ubuntu·12:37 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-44954?

CVE-2024-44954 has a moderate severity level due to its ability to cause concurrency issues in the ALSA line6 driver.

2

How do I fix CVE-2024-44954?

To fix CVE-2024-44954, update your Linux kernel to version 5.10.226-1, 6.1.123-1, or apply the respective patches mentioned in the advisory.

3

What systems are affected by CVE-2024-44954?

CVE-2024-44954 affects multiple versions of the Linux kernel, specifically those before 5.10.224 and kernel version 6.11-rc2.

4

What is the potential impact of CVE-2024-44954?

The potential impact of CVE-2024-44954 includes possible denial of service or abnormal system behavior due to concurrent access issues.

5

Who is impacted by CVE-2024-44954?

Users and administrators of affected Linux distributions using the ALSA line6 driver may experience risks associated with CVE-2024-44954.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203