CVE-2024-57893: ALSA: seq: oss: Fix races at processing SysEx messages
ALSA: seq: oss: Fix races at processing SysEx messages
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57893?
The severity of CVE-2024-57893 is considered moderate due to the potential for race conditions in processing SysEx messages.
How do I fix CVE-2024-57893?
To fix CVE-2024-57893, update your Linux kernel to the latest version where this vulnerability has been resolved.
Which versions of the Linux kernel are affected by CVE-2024-57893?
CVE-2024-57893 affects multiple versions of the Linux kernel that include the OSS sequencer functionality.
What potential impact does CVE-2024-57893 have on system security?
CVE-2024-57893 could lead to unexpected behavior or crashes in the ALSA OSS sequencer when handling SysEx messages.
Is CVE-2024-57893 a local or remote vulnerability?
CVE-2024-57893 is primarily a local vulnerability, affecting users with access to the system that can interact with the ALSA OSS layer.