CVE-2024-38551: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Assign dummy when codec not specified for a DAI link MediaTek sound card drivers are checking whether a DAI link is present and used on a board to assign the correct parameters and this is done by checking the codec DAI names at probe time. If no real codec is present, assign the dummy codec to the DAI link to avoid NULL pointer during string comparison.

Affected products

  • Linux Linux Kernel: from 6.3, before 6.6.33 (fixed in 6.6.33); from 6.7, before 6.8.12 (fixed in 6.8.12); from 6.9, before 6.9.3 (fixed in 6.9.3)

Published 2024-06-19. Last modified 2026-06-17.