CVE-2023-52697
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name. For example, rt712 and rt713 both use "rt712-sdca-aif1" and sof_sdw_rt_sdca_jack_exit(). As a result, sof_sdw_rt_sdca_jack_exit() will be called twice by mc_dailink_exit_loop(). Set ctx->headset_codec_dev = NULL; after put_device(ctx->headset_codec_dev); to avoid ctx->headset_codec_dev being put twice.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9efPatch
- https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3dPatch
- https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416Patch
- https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9efPatch
- https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3dPatch
- https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.