PT-2024-29179 · Linux+5 · Linux Kernel+5

Simon Trimmer

·

Published

2024-05-31

·

Updated

2025-09-29

·

CVE-2024-40964

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a possible null pointer dereference in the cs35l41 hda unbind() function. This function clears the hda component entry matching its index and then dereferences the codec pointer held in the first element of the hda component array. The problem arises when the device index is 0. To resolve this, the codec pointer stashed in the cs35l41 hda structure should be used instead, as it will still be valid.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
BDU:2025-03410
CVE-2024-40964
OESA-2024-1863
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6999-1
USN-6999-2
USN-7004-1
USN-7005-1
USN-7005-2
USN-7008-1
USN-7029-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu