PT-2024-28088 · Linux+5 · Linux Kernel+5

Chris Wulff

·

Published

2024-04-25

·

Updated

2026-05-26

·

CVE-2024-38628

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition vulnerability has been resolved in the Linux kernel, specifically in the usb: gadget: u audio component. The issue occurred due to the use of controls after free during gadget unbind. To fix this, the control IDs are now held onto instead of pointers, as these are correctly handled with locks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Race Condition

Weakness Enumeration

Related Identifiers

AZL-58983
BDU:2025-02948
CVE-2024-38628
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1836
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu