ALSA: asihpi: Fix potential OOB array access
Published Oct 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.25%
Description
ASIHPI driver stores some values in the static array upon a response from the driver, and its index depends on the firmware. We shouldn't trust it blindly.
This patch adds a sanity check of the array index to fit in the array size.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.35StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.35
- Version 4.19.323StatusunaffectedConstraints<=4.19.*
- Version 5.10.227StatusunaffectedConstraints<=5.10.*
- Version 5.15.168StatusunaffectedConstraints<=5.15.*
- Version 5.4.285StatusunaffectedConstraints<=5.4.*
- Version 6.1.113StatusunaffectedConstraints<=6.1.*
- Version 6.10.14StatusunaffectedConstraints<=6.10.*
- Version 6.11.3StatusunaffectedConstraints<=6.11.*
- Version 6.12StatusunaffectedConstraints<=*
- Version 6.6.55StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- 11.0
Configuration 2
- < 4.19.323
- ≥ 4.20 · < 5.4.285
- ≥ 5.5 · < 5.10.227
- ≥ 5.11 · < 5.15.168
- ≥ 5.16 · < 6.1.113
- ≥ 6.2 · < 6.6.55
- ≥ 6.7 · < 6.10.14
- ≥ 6.11 · < 6.11.3
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Will not fix
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is considered to be a moderate impact flaw, as the exploitation for this will need an ADMIN (or ROOT) privilege (PR:H).
Red Hat mitigation
If the HPI audio hardware is not in use, prevent the `asihpi` kernel module from loading to mitigate this vulnerability. Create a file such as `/etc/modprobe.d/disable-asihpi.conf` with the following content: ``` install asihpi /bin/true ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This action may impact functionality if HPI audio hardware is present and in use.
References (16)
- https://access.redhat.com/security/cve/CVE-2024-50007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320564 Issue Tracking
- https://git.kernel.org/stable/c/219587bca2678e31700ef09ecec178ba1f735674 Patch
- https://git.kernel.org/stable/c/36ee4021bcc37b834996e79740d095d6f8dd948f Patch
- https://git.kernel.org/stable/c/7a55740996701f7b2bc46dc988b60ef2e416a747 Patch
- https://git.kernel.org/stable/c/7b986c7430a6bb68d523dac7bfc74cbd5b44ef96 Patch
- https://git.kernel.org/stable/c/876d04bf5a8ac1d6af5afd258cd37ab83ab2cf3d Patch
- https://git.kernel.org/stable/c/a6bdb691cf7b66dcd929de1a253c5c42edd2e522 Patch
- https://git.kernel.org/stable/c/ad7248a5e92587b9266c62db8bcc4e58de53e372 Patch
- https://git.kernel.org/stable/c/ce2953e44829ec54bcbb57e9d890fc8af0900c80 Patch
- https://git.kernel.org/stable/c/e658227d9d4f4e122d81690fdbc0d438b10288f5 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html Mailing ListThird Party Advisory
- https://lore.kernel.org/linux-cve-announce/2024102109-CVE-2024-50007-0253@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-50007
- https://www.cve.org/CVERecord?id=CVE-2024-50007
Change history (0)
No recorded changes yet.