In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Don't setup bogus iov_iter for silencing At transition to the iov_iter for PCM data transfer, we blindly applied the iov_iter setup also for silencing (i.e. data = NULL), and it leads to a calculation of bogus iov_iter. Fortunately this didn't cause troubles on most of architectures but it goes wrong on RISC-V now, causing a NULL dereference. Handle the NULL data case to treat the silencing in interleaved_copy() for addressing the bug above. noninterleaved_copy() has already the NULL data handling, so it doesn't need changes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.6CNA affecteddefault affected | |
| Linux | Linux | >= cf393babb37a1679a1ec1d864df1090353465e23, < 41a766c647294842c9b17672449f8e011048cba9, >= cf393babb37a1679a1ec1d864df1090353465e23, < c9f6768515818d71bdfc20119a81f3332c53b9c6, >= cf393babb37a1679a1ec1d864df1090353465e23, < ce836587e594af39ff048d9b29dee0f5f10692c9, >= cf393babb37a1679a1ec1d864df1090353465e23, < e4d3386b74fba8e01280484b67ee481ece00201e, >= cf393babb37a1679a1ec1d864df1090353465e23, < feff0251386aa6bb180a0a1cf7c1f91ba868113dCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.