PT-2024-6984 · Linux+6 · Linux Kernel+6

Published

2024-09-11

·

Updated

2025-09-29

·

CVE-2024-46849

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.9.12-sdkernel
Description The issue is related to a 'use-after-free' vulnerability in the ASoC: meson: axg-card component of the Linux kernel. The buffer 'card->dai link' is reallocated in 'meson card reallocate links()', and the 'pad' pointer initialization needs to be moved after this function when memory is already reallocated. A Kasan bug report indicates a slab-use-after-free in axg card add link+0x76c/0x9bc.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the 'use-after-free' vulnerability in the ASoC: meson: axg-card component. As a temporary workaround, consider disabling the axg card add link() function until a patch is available. Restrict access to the vulnerable module snd soc meson axg sound card to minimize the risk of exploitation. Avoid using the card->dai link buffer in the affected API endpoint until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-49795
AZL-49858
BDU:2024-08233
CVE-2024-46849
DLA-4008-1
DLA-4075-1
DSA-5782-1
OESA-2024-2216
OESA-2024-2218
OESA-2024-2219
OESA-2024-2220
OESA-2024-2256
OPENSUSE-SU-2024_3983-1
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3985-1
OPENSUSE-SU-2024_3986-1
OPENSUSE-SU-2024_4131-1
OPENSUSE-SU-2024_4140-1
SUSE-SU-2024:3983-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3985-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4081-1
SUSE-SU-2024:4082-1
SUSE-SU-2024:4103-1
SUSE-SU-2024:4131-1
SUSE-SU-2024:4140-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1
USN-7196-1
USN-7293-1
USN-7294-1
USN-7294-2
USN-7294-3
USN-7294-4
USN-7295-1
USN-7393-1
USN-7401-1
USN-7413-1
USN-7539-1
USN-7540-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu