-

CVE-2023-54084

ALSA: firewire-digi00x: prevent potential use after free

In the Linux kernel, the following vulnerability has been resolved:

ALSA: firewire-digi00x: prevent potential use after free

This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 9a08067ec318cbeaf0caa2d104cf677e723e02a3
Version < 5009aead17f060753428e249eb0246eb1c2f8b86
Status affected
Version 9a08067ec318cbeaf0caa2d104cf677e723e02a3
Version < 13c5fa1248bf06e95a25907c1be83948b8c44c50
Status affected
Version 9a08067ec318cbeaf0caa2d104cf677e723e02a3
Version < bbb5ac533ca6c4e2775a95388c9c0c610bb442b7
Status affected
Version 9a08067ec318cbeaf0caa2d104cf677e723e02a3
Version < ee1a221d947809c0308f27567c07a3ac93406057
Status affected
Version 9a08067ec318cbeaf0caa2d104cf677e723e02a3
Version < 67148395efa2c1fb20e98fca359b20e7a6c81fe4
Status affected
Version 9a08067ec318cbeaf0caa2d104cf677e723e02a3
Version < c0e72058d5e21982e61a29de6b098f7c1f0db498
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.4
Status affected
Version 0
Version < 5.4
Status unaffected
Version <= 5.4.*
Version 5.4.244
Status unaffected
Version <= 5.10.*
Version 5.10.181
Status unaffected
Version <= 5.15.*
Version 5.15.113
Status unaffected
Version <= 6.1.*
Version 6.1.30
Status unaffected
Version <= 6.3.*
Version 6.3.4
Status unaffected
Version <= *
Version 6.4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.144
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.