CVE-2024-40964: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Possible null pointer dereference in cs35l41_hda_unbind() The cs35l41_hda_unbind() function clears the hda_component entry matching it's index and then dereferences the codec pointer held in the first element of the hda_component array, this is an issue when the device index was 0. Instead use the codec pointer stashed in the cs35l41_hda structure as it will still be valid.

Affected products

  • Linux Linux Kernel: from 6.6, before 6.6.36 (fixed in 6.6.36); from 6.7, before 6.9.7 (fixed in 6.9.7); version 6.10 only

Published 2024-07-12. Last modified 2026-06-17.