ALSA: core: Fix NULL module pointer assignment at card init

Summary

CVECVE-2024-38605
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-06-19 14:15:20 UTC
Updated2026-08-04 11:18:50 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card object creation, and it also wraps the code around it with '#ifdef MODULE'. This works in most cases, but the devils are always in details. "MODULE" is defined when the target code (i.e. the sound core) is built as a module; but this doesn't mean that the caller is also built-in or not. Namely, when only the sound core is built-in (CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m), the passed module pointer is ignored even if it's non-NULL, and card->module remains as NULL. This would result in the missing module reference up/down at the device open/close, leading to a race with the code execution after the module removal. For addressing the bug, move the assignment of card->module again out of ifdef. The WARN_ON() is still wrapped with ifdef because the module can be really NULL when all sound drivers are built-in. Note that we keep 'ifdef MODULE' for WARN_ON(), otherwise it would lead to a false-positive NULL module check. Admittedly it won't catch perfectly, i.e. no check is performed when CONFIG_SND=y. But, it's no real problem as it's only for debugging, and the condition is pretty rare.

Risk And Classification

Primary CVSS: v3.1 8.8 HIGH from ADP

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem Types: CWE-476 | CWE-476 CWE-476 NULL Pointer Dereference


VersionSourceTypeScoreSeverityVector
3.1ADPDECLARED8.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1134c704f-9b21-4f2e-91b3-4a467353bcc0Secondary8.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 d7ff29a429b56f04783152ad7bbd7233b740e434 git Not specified
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 e7e0ca200772bdb2fdc6d43d32d341e87a36f811 git Not specified
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 e007476725730c1a68387b54b7629486d8a8301e git Not specified
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92 git Not specified
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 c935e72139e6d523defd60fe875c01eb1f9ea5c5 git Not specified
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 6b8374ee2cabcf034faa34e69a855dc496a9ec12 git Not specified
CNA Linux Linux affected 81033c6b584b44514cbb16fffc26ca29a0fa6270 39381fe7394e5eafac76e7e9367e7351138a29c1 git Not specified
CNA Linux Linux affected 5.9 Not specified
CNA Linux Linux unaffected 5.9 semver Not specified
CNA Linux Linux unaffected 5.10.219 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.161 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.93 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.33 6.6.* semver Not specified
CNA Linux Linux unaffected 6.8.12 6.8.* semver Not specified
CNA Linux Linux unaffected 6.9.3 6.9.* semver Not specified
CNA Linux Linux unaffected 6.10 * original_commit_for_fix Not specified
ADP Linux Linux Kernel affected 81033c6b584b d7ff29a429b5 custom Not specified
ADP Linux Linux Kernel affected 81033c6b584b e7e0ca200772 custom Not specified
ADP Linux Linux Kernel affected 81033c6b584b e00747672573 custom Not specified
ADP Linux Linux Kernel affected 81033c6b584b e644036a3e2b custom Not specified
ADP Linux Linux Kernel affected 81033c6b584b c935e72139e6 custom Not specified
ADP Linux Linux Kernel affected 81033c6b584b 6b8374ee2cab custom Not specified
ADP Linux Linux Kernel affected 81033c6b584b 39381fe7394e custom Not specified
ADP Linux Linux Kernel affected 5.9 Not specified
ADP Linux Linux Kernel unaffected 5.9 custom Not specified
ADP Linux Linux Kernel unaffected 5.10.219 5.11 custom Not specified
ADP Linux Linux Kernel unaffected 5.15.161 5.16 custom Not specified
ADP Linux Linux Kernel unaffected 6.1.93 6.2 custom Not specified
ADP Linux Linux Kernel unaffected 6.6.33 6.7 custom Not specified
ADP Linux Linux Kernel unaffected 6.8.12 6.9 custom Not specified
ADP Linux Linux Kernel unaffected 6.9.3 6.7 custom Not specified
ADP Linux Linux Kernel unaffected 6.10-rc1 Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e7e0ca200772bdb2fdc6d43d32d341e87a36f811 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/c935e72139e6d523defd60fe875c01eb1f9ea5c5 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/e007476725730c1a68387b54b7629486d8a8301e af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/d7ff29a429b56f04783152ad7bbd7233b740e434 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/39381fe7394e5eafac76e7e9367e7351138a29c1 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/6b8374ee2cabcf034faa34e69a855dc496a9ec12 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
git.kernel.org/stable/c/e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92 af854a3a-2127-422b-91ae-364da2661108 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report