In the Linux kernel, the following vulnerability has been resolved:
ALSA: scarlett2: Add clamp() in scarlett2mixerctl_put()
Ensure the value passed to scarlett2mixerctlput() is between 0 and SCARLETT2MIXERMAXVALUE so we don't attempt to access outside scarlett2mixervalues[].
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e517645ead5ea22c69d2a44694baa23fe1ce7c2b",
"target": {
"file": "sound/usb/mixer_scarlett_gen2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-48578245",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262984715473350338890095435386298056020",
"21938690786662838746041805711241084264",
"133120078029038002083254913041089907407",
"323059565052843981442779321448405848584"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@03035872e17897ba89866940bbc9cefca601e572",
"target": {
"file": "sound/usb/mixer_scarlett_gen2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-593566ad",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262984715473350338890095435386298056020",
"21938690786662838746041805711241084264",
"133120078029038002083254913041089907407",
"323059565052843981442779321448405848584"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ad945ea8d47dd4454c271510bea24850119847c2",
"target": {
"function": "scarlett2_mixer_ctl_put",
"file": "sound/usb/mixer_scarlett2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-906c5299",
"digest": {
"length": 694.0,
"function_hash": "200970239807082715127105698996508171736"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@04f8f053252b86c7583895c962d66747ecdc61b7",
"target": {
"function": "scarlett2_mixer_ctl_put",
"file": "sound/usb/mixer_scarlett2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-96cfbe28",
"digest": {
"length": 694.0,
"function_hash": "200970239807082715127105698996508171736"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e517645ead5ea22c69d2a44694baa23fe1ce7c2b",
"target": {
"function": "scarlett2_mixer_ctl_put",
"file": "sound/usb/mixer_scarlett_gen2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-bba8fe13",
"digest": {
"length": 694.0,
"function_hash": "200970239807082715127105698996508171736"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@03035872e17897ba89866940bbc9cefca601e572",
"target": {
"function": "scarlett2_mixer_ctl_put",
"file": "sound/usb/mixer_scarlett_gen2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-c0835217",
"digest": {
"length": 694.0,
"function_hash": "200970239807082715127105698996508171736"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d8d8897d65061cbe36bf2909057338303a904810",
"target": {
"function": "scarlett2_mixer_ctl_put",
"file": "sound/usb/mixer_scarlett_gen2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-c1677e57",
"digest": {
"length": 694.0,
"function_hash": "200970239807082715127105698996508171736"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ad945ea8d47dd4454c271510bea24850119847c2",
"target": {
"file": "sound/usb/mixer_scarlett2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-c45aca93",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262984715473350338890095435386298056020",
"21938690786662838746041805711241084264",
"133120078029038002083254913041089907407",
"323059565052843981442779321448405848584"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@04f8f053252b86c7583895c962d66747ecdc61b7",
"target": {
"file": "sound/usb/mixer_scarlett2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-d1659ebc",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262984715473350338890095435386298056020",
"21938690786662838746041805711241084264",
"133120078029038002083254913041089907407",
"323059565052843981442779321448405848584"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d8d8897d65061cbe36bf2909057338303a904810",
"target": {
"file": "sound/usb/mixer_scarlett_gen2.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-52674-ef5d0967",
"digest": {
"threshold": 0.9,
"line_hashes": [
"262984715473350338890095435386298056020",
"21938690786662838746041805711241084264",
"133120078029038002083254913041089907407",
"323059565052843981442779321448405848584"
]
},
"signature_type": "Line"
}
]