Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array The code uses the initialised member of the asoc_sdw_dailink struct to determine if a member of the array is in use. However in the case the array is completely full this will lead to an access 1 past the end of the array, expand the array by one entry to include a space for a terminator.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.10, < 6.12.6 |
References
- https://git.kernel.org/stable/c/255cc582e6e16191a20d54bcdbca6c91d3e90c5ePatch
- https://git.kernel.org/stable/c/b21a849764a4111b0bc14a5ffe987a0582419de2Patch
FAQ
What is CVE-2024-57880?
CVE-2024-57880 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array The code uses the initialised member of the asoc_sdw_dailink stru...
How severe is CVE-2024-57880?
CVE-2024-57880 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57880?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.