PT-2024-29743 · Linux+2 · Linux Kernel+2

Published

2024-06-24

·

Updated

2024-12-12

·

CVE-2024-42088

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue is related to the ASoC (Audio System on Chip) component, specifically the mediatek mt8195 driver. A commit removed the codec entry for the ETDM1 OUT BE dai link entirely instead of replacing it with COMP EMPTY(), causing the remaining COMP EMPTY() platform entry to become the codec entry. This results in a KASAN out-of-bounds warning in the mtk soundcard common probe() function. The warning occurs because the code expects the platforms array to have space for at least one entry. To fix this, an COMP EMPTY() entry needs to be added so that dai link->platforms has space.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03545
CVE-2024-42088
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu