Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-54084

Опубликовано: 24 дек. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.

A potential use-after-free vulnerability was found in the Linux kernel's ALSA firewire-digi00x driver. When init_stream() fails, the error handling code incorrectly frees dg00x->rx_stream but returns success instead of an error code. This leaves a dangling pointer that can be dereferenced later, leading to a use-after-free condition.

Отчет

This flaw affects systems with Digidesign Digi 002/003 FireWire audio interfaces using the snd-firewire-digi00x driver. The use-after-free can occur when stream initialization fails, which is an uncommon error condition during device setup. Physical access to connect the specific hardware is required.

Меры по смягчению последствий

To mitigate this issue, prevent the snd_firewire_digi00x module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2425117kernel: ALSA: firewire-digi00x: prevent potential use after free

EPSS

Процентиль: 9%
0.00187
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.

nvd
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.

debian
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: A ...

github
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость функции snd_dg00x_stream_init_duplex() модуля sound/firewire/digi00x/digi00x-stream.c звуковой подсистемы ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00187
Низкий

5.5 Medium

CVSS3