Lucene search

K
osvGoogleOSV:CVE-2024-42089
HistoryJul 29, 2024 - 5:15 p.m.

CVE-2024-42089

2024-07-2917:15:11
Google
osv.dev
5
linux kernel
vulnerability
asoc
fsl-asoc-card

AI Score

8.2

Confidence

High

In the Linux kernel, the following vulnerability has been resolved:

ASoC: fsl-asoc-card: set priv->pdev before using it

priv->pdev pointer was set after being used in
fsl_asoc_card_audmux_init().
Move this assignment at the start of the probe function, so
sub-functions can correctly use pdev through priv.

fsl_asoc_card_audmux_init() dereferences priv->pdev to get access to the
dev struct, used with dev_err macros.
As priv is zero-initialised, there would be a NULL pointer dereference.
Note that if priv->dev is dereferenced before assignment but never used,
for example if there is no error to be printed, the driver won’t crash
probably due to compiler optimisations.