In the Linux kernel, the following vulnerability has been resolved:
ASoC: fsl-asoc-card: set priv->pdev before using it
priv->pdev pointer was set after being used in
fsl_asoc_card_audmux_init().
Move this assignment at the start of the probe function, so
sub-functions can correctly use pdev through priv.
fsl_asoc_card_audmux_init() dereferences priv->pdev to get access to the
dev struct, used with dev_err macros.
As priv is zero-initialised, there would be a NULL pointer dereference.
Note that if priv->dev is dereferenced before assignment but never used,
for example if there is no error to be printed, the driver won’t crash
probably due to compiler optimisations.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 20.04 | noarch | linux | < any | UNKNOWN |
ubuntu | 22.04 | noarch | linux | < any | UNKNOWN |
ubuntu | 24.04 | noarch | linux | < any | UNKNOWN |
ubuntu | 20.04 | noarch | linux-aws | < any | UNKNOWN |
ubuntu | 22.04 | noarch | linux-aws | < any | UNKNOWN |
ubuntu | 24.04 | noarch | linux-aws | < any | UNKNOWN |
ubuntu | 20.04 | noarch | linux-aws-5.15 | < any | UNKNOWN |
ubuntu | 20.04 | noarch | linux-azure | < any | UNKNOWN |
ubuntu | 22.04 | noarch | linux-azure | < any | UNKNOWN |
ubuntu | 24.04 | noarch | linux-azure | < any | UNKNOWN |
git.kernel.org/linus/90f3feb24172185f1832636264943e8b5e289245 (6.10-rc6)
git.kernel.org/stable/c/29bc9e7c75398b0d12fc30955f2e9b2dd29ffaed
git.kernel.org/stable/c/3662eb2170e59b58ad479982dc1084889ba757b9
git.kernel.org/stable/c/544ab46b7ece6d6bebbdee5d5659c0a0f804a99a
git.kernel.org/stable/c/7c18b4d89ff9c810b6e562408afda5ce165c4ea6
git.kernel.org/stable/c/8896e18b7c366f8faf9344abfd0971435f1c723a
git.kernel.org/stable/c/8faf91e58425c2f6ce773250dfd995f1c2d461ac
git.kernel.org/stable/c/90f3feb24172185f1832636264943e8b5e289245
git.kernel.org/stable/c/ae81535ce2503aabc4adab3472f4338070cdeb6a
launchpad.net/bugs/cve/CVE-2024-42089
nvd.nist.gov/vuln/detail/CVE-2024-42089
security-tracker.debian.org/tracker/CVE-2024-42089
www.cve.org/CVERecord?id=CVE-2024-42089