Answer in brief
CVE-2023-52988 records a Unknown severity vulnerability in ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2023-52988 records a Unknown severity vulnerability in ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=30b4503378c976cf66201a1e81820519f6bd79ac <437e50ef6290ac835d526d0e45f466a0aa69ba1b || >=30b4503378c976cf66201a1e81820519f6bd79ac <6e1f586ddec48d71016b81acf68ba9f49ca54db8 || >=30b4503378c976cf66201a1e81820519f6bd79ac <d6870f3800dbb212ae8433183ee82f566d067c6c || >=30b4503378c976cf66201a1e81820519f6bd79ac <2b557fa635e7487f638c0f030c305870839eeda2 || >=30b4503378c976cf66201a1e81820519f6bd79ac <1b9256c96220bcdba287eeeb90e7c910c77f8c46 || >=30b4503378c976cf66201a1e81820519f6bd79ac <f011360ad234a07cb6fbcc720fff646a93a9f0d6 || >=30b4503378c976cf66201a1e81820519f6bd79ac <b9cee506da2b7920b5ea02ccd8e78a907d0ee7aa | 437e50ef6290ac835d526d0e45f466a0aa69ba1b, 6e1f586ddec48d71016b81acf68ba9f49ca54db8, d6870f3800dbb212ae8433183ee82f566d067c6c, 2b557fa635e7487f638c0f030c305870839eeda2, 1b9256c96220bcdba287eeeb90e7c910c77f8c46, f011360ad234a07cb6fbcc720fff646a93a9f0d6, b9cee506da2b7920b5ea02ccd8e78a907d0ee7aa |
| Linux/Linuxgeneric | 3.1 | Not reported |
Published upstream
Mar 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path() snd_hda_get_connections() can return a negative error code. It may lead to accessing 'conn' array at a negative index. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=30b4503378c976cf66201a1e81820519f6bd79ac <437e50ef6290ac835d526d0e45f466a0aa69ba1b || >=30b4503378c976cf66201a1e81820519f6bd79ac <6e1f586ddec48d71016b81acf68ba9f49ca54db8 || >=30b4503378c976cf66201a1e81820519f6bd79ac <d6870f3800dbb212ae8433183ee82f566d067c6c || >=30b4503378c976cf66201a1e81820519f6bd79ac <2b557fa635e7487f638c0f030c305870839eeda2 || >=30b4503378c976cf66201a1e81820519f6bd79ac <1b9256c96220bcdba287eeeb90e7c910c77f8c46 || >=30b4503378c976cf66201a1e81820519f6bd79ac <f011360ad234a07cb6fbcc720fff646a93a9f0d6 || >=30b4503378c976cf66201a1e81820519f6bd79ac <b9cee506da2b7920b5ea02ccd8e78a907d0ee7aa | 437e50ef6290ac835d526d0e45f466a0aa69ba1b, 6e1f586ddec48d71016b81acf68ba9f49ca54db8, d6870f3800dbb212ae8433183ee82f566d067c6c, 2b557fa635e7487f638c0f030c305870839eeda2, 1b9256c96220bcdba287eeeb90e7c910c77f8c46, f011360ad234a07cb6fbcc720fff646a93a9f0d6, b9cee506da2b7920b5ea02ccd8e78a907d0ee7aa |
| Linux/Linuxgeneric | 3.1 | Not reported |
Published upstream
Mar 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path() snd_hda_get_connections() can return a negative error code. It may lead to accessing 'conn' array at a negative index. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Quoted source text, attributed separately from HOL analysis.