CVE-2021-46926

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: harden detection of controller The existing code currently sets a pointer to an ACPI handle before checking that it's actually a SoundWire controller. This can lead to issues where the graph walk continues and eventually fails, but the pointer was set already. This patch changes the logic so that the information provided to the caller is set when a controller is found.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:34

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/385f287f9853da402d94278e59f594501c1d1dad - Patch () https://git.kernel.org/stable/c/385f287f9853da402d94278e59f594501c1d1dad - Patch
References () https://git.kernel.org/stable/c/cce476954401e3421afafb25bbaa926050688b1d - Patch () https://git.kernel.org/stable/c/cce476954401e3421afafb25bbaa926050688b1d - Patch

10 Apr 2024, 16:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/385f287f9853da402d94278e59f594501c1d1dad - () https://git.kernel.org/stable/c/385f287f9853da402d94278e59f594501c1d1dad - Patch
References () https://git.kernel.org/stable/c/cce476954401e3421afafb25bbaa926050688b1d - () https://git.kernel.org/stable/c/cce476954401e3421afafb25bbaa926050688b1d - Patch

27 Feb 2024, 14:20

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ALSA: hda: intel-sdw-acpi: reforzar la detección del controlador El código existente actualmente establece un puntero a un identificador ACPI antes de verificar que en realidad es un controlador SoundWire. Esto puede provocar problemas en los que el recorrido del gráfico continúa y finalmente falla, pero el puntero ya estaba configurado. Este parche cambia la lógica para que la información proporcionada a la persona que llama se establezca cuando se encuentra un controlador.

27 Feb 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-27 10:15

Updated : 2024-11-21 06:34


NVD link : CVE-2021-46926

Mitre link : CVE-2021-46926

CVE.ORG link : CVE-2021-46926


JSON object : View

Products Affected

linux

  • linux_kernel