CVE-2024-39473: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a process module does not have base config extension then the same format applies to all of it's inputs and the process->base_config_ext is NULL, causing NULL dereference when specifically crafted topology and sequences used.
Affected products
- Linux Linux Kernel: before 6.4 (fixed in 6.4); from 6.6, before 6.6.34 (fixed in 6.6.34); from 6.9, before 6.9.5 (fixed in 6.9.5); version 6.10.0 only
Published 2024-07-05. Last modified 2026-06-17.