Executive Summary

Informations
Name CVE-2024-41037 First vendor Publication 2024-07-29
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: Intel: hda: fix null deref on system suspend entry

When system enters suspend with an active stream, SOF core calls hw_params_upon_resume(). On Intel platforms with HDA DMA used to manage the link DMA, this leads to call chain of

hda_dsp_set_hw_params_upon_resume()
-> hda_dsp_dais_suspend()
-> hda_dai_suspend()
-> hda_ipc4_post_trigger()

A bug is hit in hda_dai_suspend() as hda_link_dma_cleanup() is run first, which clears hext_stream->link_substream, and then hda_ipc4_post_trigger() is called with a NULL snd_pcm_substream pointer.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41037

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-476 NULL Pointer Dereference

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3635

Sources (Detail)

https://git.kernel.org/stable/c/8246bbf818ed7b8d5afc92b951e6d562b45c2450
https://git.kernel.org/stable/c/9065693dcc13f287b9e4991f43aee70cf5538fdd
https://git.kernel.org/stable/c/993af0f2d9f24e3c18a445ae22b34190d1fcad61
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
Date Informations
2025-01-08 03:03:45
  • Multiple Updates
2025-01-07 03:03:18
  • Multiple Updates
2024-12-25 03:01:55
  • Multiple Updates
2024-12-12 03:04:53
  • Multiple Updates
2024-11-25 09:23:28
  • Multiple Updates
2024-11-22 21:22:43
  • Multiple Updates
2024-11-21 21:22:14
  • Multiple Updates
2024-11-20 02:58:31
  • Multiple Updates
2024-11-14 02:58:49
  • Multiple Updates
2024-11-09 02:58:50
  • Multiple Updates
2024-10-26 02:56:14
  • Multiple Updates
2024-10-25 02:58:09
  • Multiple Updates
2024-10-23 02:57:21
  • Multiple Updates
2024-10-03 02:52:41
  • Multiple Updates
2024-10-02 02:51:05
  • Multiple Updates
2024-09-15 02:48:51
  • Multiple Updates
2024-09-12 02:48:24
  • Multiple Updates
2024-09-07 02:47:23
  • Multiple Updates
2024-09-06 02:46:33
  • Multiple Updates
2024-09-04 02:49:46
  • Multiple Updates
2024-08-22 02:47:43
  • Multiple Updates
2024-08-08 21:28:01
  • Multiple Updates
2024-07-29 21:27:27
  • First insertion