CVE-2024-46863
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Sep 27, 2024
Updated: Oct 3, 2024
Summary
CVE-2024-46863 is a vulnerability affecting the Linux kernel's ASoC (Advanced Sound Architecture) subsystem. Specifically, in the Intel driver's soc-acpi-intel-lnl-match component, a missing empty item in the struct snd_soc_acpi_link_adr array has been identified. This oversight causes the hda_sdw_machine_select() function to test a nonexistent link_num value in struct snd_soc_acpi_mach, potentially leading to an infinite loop or other unintended behavior. This issue has been addressed in a recent kernel update.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.