CVE-2024-44954

Source
https://cve.org/CVERecord?id=CVE-2024-44954
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44954.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-44954
Downstream
Related
Published
2024-09-04T18:35:53.730Z
Modified
2026-05-07T04:16:31.455721Z
Summary
ALSA: line6: Fix racy access to midibuf
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: line6: Fix racy access to midibuf

There can be concurrent accesses to line6 midibuf from both the URB completion callback and the rawmidi API access. This could be a cause of KMSAN warning triggered by syzkaller below (so put as reported-by here).

This patch protects the midibuf call of the former code path with a spinlock for avoiding the possible races.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/44xxx/CVE-2024-44954.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
705ececd1c60d0f5d6ef2a719008847883516970
Fixed
643293b68fbb6c03f5e907736498da17d43f0d81
Fixed
40f3d5cb0e0cbf7fa697913a27d5d361373bdcf5
Fixed
e7e7d2b180d8f297cea6db43ea72402fd33e1a29
Fixed
a54da4b787dcac60b598da69c9c0072812b8282d
Fixed
c80f454a805443c274394b1db0d1ebf477abd94e
Fixed
535df7f896a568a8a1564114eaea49d002cb1747
Fixed
51d87f11dd199bbc6a85982b088ff27bde53b48a
Fixed
15b7a03205b31bc5623378c190d22b7ff60026f1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44954.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.30
Fixed
4.19.320
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.282
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.224
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.165
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.105
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.46
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.10.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-44954.json"