{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-46798", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-09-11T15:12:18.280Z", "datePublished": "2024-09-18T07:12:52.628Z", "dateUpdated": "2026-08-05T11:38:37.461Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:38:37.461Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: Fix UAF for snd_soc_pcm_runtime object\n\nWhen using kernel with the following extra config,\n\n - CONFIG_KASAN=y\n - CONFIG_KASAN_GENERIC=y\n - CONFIG_KASAN_INLINE=y\n - CONFIG_KASAN_VMALLOC=y\n - CONFIG_FRAME_WARN=4096\n\nkernel detects that snd_pcm_suspend_all() access a freed\n'snd_soc_pcm_runtime' object when the system is suspended, which\nleads to a use-after-free bug:\n\n[ 52.047746] BUG: KASAN: use-after-free in snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047765] Read of size 1 at addr ffff0000b9434d50 by task systemd-sleep/2330\n\n[ 52.047785] Call trace:\n[ 52.047787] dump_backtrace+0x0/0x3c0\n[ 52.047794] show_stack+0x34/0x50\n[ 52.047797] dump_stack_lvl+0x68/0x8c\n[ 52.047802] print_address_description.constprop.0+0x74/0x2c0\n[ 52.047809] kasan_report+0x210/0x230\n[ 52.047815] __asan_report_load1_noabort+0x3c/0x50\n[ 52.047820] snd_pcm_suspend_all+0x1a8/0x270\n[ 52.047824] snd_soc_suspend+0x19c/0x4e0\n\nThe snd_pcm_sync_stop() has a NULL check on 'substream->runtime' before\nmaking any access. So we need to always set 'substream->runtime' to NULL\neverytime we kfree() it." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is in the ALSA SoC DAPM layer and is reached through local interfaces — ALSA control/PCM device nodes (/dev/snd/*) that power the codec2codec DAI-link widget up and down, and a local system-suspend request. There is no network-facing input path.\nAC:L - The stale pointer is left deterministically on every POST_PMD power-down and persists indefinitely; there is no race and no unpredictable state, and the attacker drives both the free (stream/route toggle) and the use (suspend) at will.\nPR:L - An unprivileged local user with normal audio access (audio group or session ACL on /dev/snd/controlC0, as granted to any logged-in user on desktops, phones and embedded systems) can power-cycle the DAPM route and request suspend; no root or CAP_* capability is needed.\nUI:N - The attacker performs every step themselves — the DAPM power-down that frees the object and the suspend that dereferences it (via logind on an active session, or simply waiting for the automatic suspend that phones, laptops and embedded targets perform routinely). No separate victim action is required.\nS:U - The use-after-free occurs in kernel memory and its impact is confined to the same kernel security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:H - The freed struct snd_pcm_runtime comes from a generic kmalloc cache and can be reclaimed by attacker-sprayed data, and the resulting corruption of a groomed victim object (e.g. clearing a length/offset/flag byte) can be leveraged into out-of-bounds kernel memory disclosure.\nI:H - snd_pcm_sync_stop() not only reads but conditionally writes to the freed object (substream->runtime->stop_operating = false), giving a controlled one-byte zeroing write at a fixed offset inside an attacker-reclaimed heap object — a real corruption primitive usable for privilege escalation.\nA:H - The use-after-free reliably corrupts or reads freed slab memory during system suspend, producing kernel oops/panic (immediately fatal under KASAN or panic_on_oops) and rendering the system unavailable." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "sound/soc/soc-dapm.c" ], "versions": [ { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "993b60c7f93fa1d8ff296b58f646a867e945ae89", "status": "affected", "versionType": "git" }, { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "8ca21e7a27c66b95a4b215edc8e45e5d66679f9f", "status": "affected", "versionType": "git" }, { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "3033ed903b4f28b5e1ab66042084fbc2c48f8624", "status": "affected", "versionType": "git" }, { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "fe5046ca91d631ec432eee3bdb1f1c49b09c8b5e", "status": "affected", "versionType": "git" }, { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "5d13afd021eb43868fe03cef6da34ad08831ad6d", "status": "affected", "versionType": "git" }, { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "6a14fad8be178df6c4589667efec1789a3307b4e", "status": "affected", "versionType": "git" }, { "version": "a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0", "lessThan": "b4a90b543d9f62d3ac34ec1ab97fc5334b048565", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "sound/soc/soc-dapm.c" ], "versions": [ { "version": "5.4", "status": "affected" }, { "version": "0", "lessThan": "5.4", "status": "unaffected", "versionType": "semver" }, { "version": "5.4.284", "lessThanOrEqual": "5.4.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.226", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.167", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.110", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.51", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.10", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "5.4.284" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "5.10.226" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "5.15.167" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.1.110" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.6.51" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.10.10" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/993b60c7f93fa1d8ff296b58f646a867e945ae89" }, { "url": "https://git.kernel.org/stable/c/8ca21e7a27c66b95a4b215edc8e45e5d66679f9f" }, { "url": "https://git.kernel.org/stable/c/3033ed903b4f28b5e1ab66042084fbc2c48f8624" }, { "url": "https://git.kernel.org/stable/c/fe5046ca91d631ec432eee3bdb1f1c49b09c8b5e" }, { "url": "https://git.kernel.org/stable/c/5d13afd021eb43868fe03cef6da34ad08831ad6d" }, { "url": "https://git.kernel.org/stable/c/6a14fad8be178df6c4589667efec1789a3307b4e" }, { "url": "https://git.kernel.org/stable/c/b4a90b543d9f62d3ac34ec1ab97fc5334b048565" } ], "title": "ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-09-29T14:22:12.387041Z", "id": "CVE-2024-46798", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-29T14:22:24.202Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" }, { "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T22:18:40.111Z" } } ] } }