Back

HIGH

ALSA: asihpi: Fix potential OOB array access

Published Oct 21, 2024

Description

ASIHPI driver stores some values in the static array upon a response from the driver, and its index depends on the firmware. We shouldn't trust it blindly.

This patch adds a sanity check of the array index to fit in the array size.

Affected products

Remediation

Red Hat statement

This issue is considered to be a moderate impact flaw, as the exploitation for this will need an ADMIN (or ROOT) privilege (PR:H).

Red Hat mitigation

If the HPI audio hardware is not in use, prevent the `asihpi` kernel module from loading to mitigate this vulnerability. Create a file such as `/etc/modprobe.d/disable-asihpi.conf` with the following content: ``` install asihpi /bin/true ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This action may impact functionality if HPI audio hardware is present and in use.

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated May 11, 2026
Reserved Oct 21, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024