In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda/cs8409: Fix possible NULL dereference
If sndhdagenaddkctl fails to allocate memory and returns NULL, then NULL pointer dereference will occur in the next line.
Since dolphinfixups function is a hdafixup function which is not supposed to return any errors, add simple check before dereference, ignore the fail.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
[
{
"id": "CVE-2024-50160-00fdfc61",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"124806267154603213009405648514613496820",
"260408852515037151779444360964224451739",
"23164501215768703565525285476163501931",
"90298814086315041368660456067625113776",
"252906389271451150475303602869384393792"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8971fd61210d75fd2af225621cd2fcc87eb1847c",
"target": {
"file": "sound/pci/hda/patch_cs8409.c"
}
},
{
"id": "CVE-2024-50160-078cdfed",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"124806267154603213009405648514613496820",
"260408852515037151779444360964224451739",
"23164501215768703565525285476163501931",
"90298814086315041368660456067625113776",
"252906389271451150475303602869384393792"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e19aca8db696b6ba4dd8c73657405e15c695f14",
"target": {
"file": "sound/pci/hda/patch_cs8409.c"
}
},
{
"id": "CVE-2024-50160-3da9a049",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"124806267154603213009405648514613496820",
"260408852515037151779444360964224451739",
"23164501215768703565525285476163501931",
"90298814086315041368660456067625113776",
"252906389271451150475303602869384393792"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a5dd71a8b849626f42d08a5e73d382f2016fc7bc",
"target": {
"file": "sound/pci/hda/patch_cs8409.c"
}
},
{
"id": "CVE-2024-50160-54de5012",
"signature_version": "v1",
"digest": {
"length": 2650.0,
"function_hash": "220893121055476296589999375547607628193"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8971fd61210d75fd2af225621cd2fcc87eb1847c",
"target": {
"file": "sound/pci/hda/patch_cs8409.c",
"function": "dolphin_fixups"
}
},
{
"id": "CVE-2024-50160-5cddae30",
"signature_version": "v1",
"digest": {
"length": 2650.0,
"function_hash": "220893121055476296589999375547607628193"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a5dd71a8b849626f42d08a5e73d382f2016fc7bc",
"target": {
"file": "sound/pci/hda/patch_cs8409.c",
"function": "dolphin_fixups"
}
},
{
"id": "CVE-2024-50160-ec60f0e8",
"signature_version": "v1",
"digest": {
"length": 2476.0,
"function_hash": "320242608107659448986875077874950624452"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4e19aca8db696b6ba4dd8c73657405e15c695f14",
"target": {
"file": "sound/pci/hda/patch_cs8409.c",
"function": "dolphin_fixups"
}
}
]