CVE-2024-38605·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card object creation, and it also wraps the code around it with '#ifdef MODULE'. This works in most cases, but the devils are always in details. "MODULE" is defined when the target code (i.e. the sound core) is built as a module; but this doesn't mean that the caller is also built-in or not. Namely, when only the sound core is built-in (CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m), the passed module pointer is ignored even if it's non-NULL, and card->module remains as NULL. This would result in the missing module reference up/down at the device open/close, leading to a race with the code execution after the module removal. For addressing the bug, move the assignment of card->module again out of ifdef. The WARN_ON() is still wrapped with ifdef because the module can be really NULL when all sound drivers are built-in. Note that we keep 'ifdef MODULE' for WARN_ON(), otherwise it would lead to a false-positive NULL module check. Admittedly it won't catch perfectly, i.e. no check is performed when CONFIG_SND=y. But, it's no real problem as it's only for debugging, and the condition is pretty rare.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.9.3
- Published
- 2024-06-19
Affected versions
From: 6.9
Until: 6.9.3
Fixed in: 6.9.3
How to fix this CVE
Update your Linux kernel to version 6.9.3 or later to resolve this module reference tracking vulnerability. This patch corrects the ALSA core initialization logic to ensure proper module pointer assignment regardless of whether the sound subsystem is built-in or modular. Affected systems should prioritize this update as it prevents potential race conditions during module removal.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your kernel version with `uname -r` and compare against 6.9.3 — vulnerable versions are 6.9, 6.9.1, 6.9.2, and 6.9.3
- Step 2: Verify ALSA/USB audio driver configuration with `lsmod | grep -E '(snd|usb_audio)'` to identify if the vulnerable code path is loaded
- Step 3: Search kernel logs for module unload warnings: `sudo dmesg | grep -i 'module.*NULL\|snd_card'` or check `/var/log/kern.log` for relevant ALSA errors
- Step 4: After patching, confirm the new kernel is active with `uname -r` showing 6.9.3 or later, then reboot if necessary and verify with `dmesg | tail -20`
FAQ
What is CVE-2024-38605?
This vulnerability affects the ALSA (Advanced Linux Sound Architecture) core when the sound subsystem is built-in to the kernel while audio drivers are compiled as modules. The module reference counter fails to increment/decrement, leading to potential use-after-free conditions if a driver is unloaded while still in use.
Is CVE-2024-38605 being actively exploited?
No — this CVE is not listed on CISA's Known Exploited Vulnerabilities catalog and no public exploits are currently available. However, the high CVSS score (8.8) warrants timely patching.
What versions of Kernel are affected by CVE-2024-38605?
Linux kernel versions 6.9, 6.9.1, 6.9.2, and early 6.9.3 are vulnerable. The fix is available in kernel 6.9.3 and later stable releases.
How do I check if my server is vulnerable to CVE-2024-38605?
Run `uname -r` to display your kernel version. If the output shows 6.9.x where x is less than 3, your system is vulnerable. Confirm ALSA is active with `lsmod | grep snd`.
Does Defensia detect CVE-2024-38605?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-38605 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/39381fe7394e5eafac76e7e9367e7351138a29c1
- https://git.kernel.org/stable/c/6b8374ee2cabcf034faa34e69a855dc496a9ec12
- https://git.kernel.org/stable/c/c935e72139e6d523defd60fe875c01eb1f9ea5c5
- https://git.kernel.org/stable/c/d7ff29a429b56f04783152ad7bbd7233b740e434
- https://git.kernel.org/stable/c/e007476725730c1a68387b54b7629486d8a8301e
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-38605. Free for 1 server.
Get started free