CVE-2023-52697
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/05/2024
Last modified:
25/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx->headset_codec_dev = NULL<br />
<br />
sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of<br />
them use the same dai name.<br />
For example, rt712 and rt713 both use "rt712-sdca-aif1" and<br />
sof_sdw_rt_sdca_jack_exit().<br />
As a result, sof_sdw_rt_sdca_jack_exit() will be called twice by<br />
mc_dailink_exit_loop(). Set ctx->headset_codec_dev = NULL; after<br />
put_device(ctx->headset_codec_dev); to avoid ctx->headset_codec_dev<br />
being put twice.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.5 (including) | 6.6.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9ef
- https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3d
- https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416
- https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9ef
- https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3d
- https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416



