PT-2024-29848 · Linux+5 · Linux Kernel+5
Published
2024-07-04
·
Updated
2025-09-29
·
CVE-2024-42298
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the ASoC component in the Linux kernel, specifically with the
fsl qmc audio module. The problem arises because the devm kasprintf() function can return a NULL pointer on failure, but this returned value is not checked. This lack of checking can lead to a NULL pointer dereference, potentially causing a denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu