<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 07:16:20 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-38605 — ALSA: core: Fix NULL module pointer assignment at card init</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-38605</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, linux_kernel&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ALSA: core: Fix NULL module pointer assignment at card init&lt;/p&gt;
&lt;p&gt;The commit 81033c6b584b (&amp;#34;ALSA: core: Warn on empty module&amp;#34;)
introduced a WARN_ON() for a NULL module pointer passed at snd_card
object creation, and it also wraps the code around it with &amp;#39;#ifdef
MODULE&amp;#39;.  This works in most cases, but the devils are always in
details.  &amp;#34;MODULE&amp;#34; is defined when the target code (i.e. the sound
core) is built as a module; but this doesn&amp;#39;t mean that the caller is
also built-in or not.  Namely, when only the sound core is built-in
(CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m),
the passed module pointer is ignored even if it&amp;#39;s non-NULL, and
card-&amp;gt;module remains as NULL.  This would result in the missing module
reference up/down at the device open/close, leading to a race with the
code execution after the module removal.&lt;/p&gt;
&lt;p&gt;For addressing the bug, move the assignment of card-&amp;gt;module again out
of ifdef.  The WARN_ON() is still wrapped with ifdef because the
module can be really NULL when all sound drivers are built-in.&lt;/p&gt;
&lt;p&gt;Note that we keep &amp;#39;ifdef MODULE&amp;#39; for WARN_ON(), otherwise it would
lead to a false-positive NULL module check.  Admittedly it won&amp;#39;t catch
perfectly, i.e. no check is performed when CONFIG_SND=y.  But, it&amp;#39;s no
real problem as it&amp;#39;s only for debugging, and the condition is pretty
rare.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, linux_kernel&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ALSA: core: Fix NULL module pointer assignment at card init&lt;/p&gt;
&lt;p&gt;The commit 81033c6b584b (&amp;#34;ALSA: core: Warn on empty module&amp;#34;)
introduced a WARN_ON() for a NULL module pointer passed at snd_card
object creation, and it also wraps the code around it with &amp;#39;#ifdef
MODULE&amp;#39;.  This works in most cases, but the devils are always in
details.  &amp;#34;MODULE&amp;#34; is defined when the target code (i.e. the sound
core) is built as a module; but this doesn&amp;#39;t mean that the caller is
also built-in or not.  Namely, when only the sound core is built-in
(CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m),
the passed module pointer is ignored even if it&amp;#39;s non-NULL, and
card-&amp;gt;module remains as NULL.  This would result in the missing module
reference up/down at the device open/close, leading to a race with the
code execution after the module removal.&lt;/p&gt;
&lt;p&gt;For addressing the bug, move the assignment of card-&amp;gt;module again out
of ifdef.  The WARN_ON() is still wrapped with ifdef because the
module can be really NULL when all sound drivers are built-in.&lt;/p&gt;
&lt;p&gt;Note that we keep &amp;#39;ifdef MODULE&amp;#39; for WARN_ON(), otherwise it would
lead to a false-positive NULL module check.  Admittedly it won&amp;#39;t catch
perfectly, i.e. no check is performed when CONFIG_SND=y.  But, it&amp;#39;s no
real problem as it&amp;#39;s only for debugging, and the condition is pretty
rare.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-38605</guid>
    </item>
  </channel>
</rss>
