Answer in brief
CVE-2024-38605 records a Unknown severity vulnerability in ALSA: core: Fix NULL module pointer assignment at card init. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), linux/linux_kernel (generic), linux/linux_kernel (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <d7ff29a429b56f04783152ad7bbd7233b740e434 || >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <e7e0ca200772bdb2fdc6d43d32d341e87a36f811 || >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <e007476725730c1a68387b54b7629486d8a8301e || >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92 || >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <c935e72139e6d523defd60fe875c01eb1f9ea5c5 || >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <6b8374ee2cabcf034faa34e69a855dc496a9ec12 || >=81033c6b584b44514cbb16fffc26ca29a0fa6270 <39381fe7394e5eafac76e7e9367e7351138a29c1 | d7ff29a429b56f04783152ad7bbd7233b740e434, e7e0ca200772bdb2fdc6d43d32d341e87a36f811, e007476725730c1a68387b54b7629486d8a8301e, e644036a3e2b2c9b3eee3c61b5d31c2ca8b5ba92, c935e72139e6d523defd60fe875c01eb1f9ea5c5, 6b8374ee2cabcf034faa34e69a855dc496a9ec12, 39381fe7394e5eafac76e7e9367e7351138a29c1 |
| Linux/Linuxgeneric | 5.9 | Not reported |
| linux/linux_kernelgeneric | >=81033c6b584b <d7ff29a429b5 | d7ff29a429b5 |
| linux/linux_kernelgeneric | >=81033c6b584b <e7e0ca200772 | e7e0ca200772 |
| linux/linux_kernelgeneric | >=81033c6b584b <e00747672573 | e00747672573 |
| linux/linux_kernelgeneric | >=81033c6b584b <e644036a3e2b | e644036a3e2b |
| linux/linux_kernelgeneric | >=81033c6b584b <c935e72139e6 | c935e72139e6 |
| linux/linux_kernelgeneric | >=81033c6b584b <6b8374ee2cab | 6b8374ee2cab |
| linux/linux_kernelgeneric | >=81033c6b584b <39381fe7394e | 39381fe7394e |
| linux/linux_kernelgeneric | 5.9 | Not reported |
Published upstream
Jun 19, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card object creation, and it also wraps the code around it with '#ifdef MODULE'. This works in most cases, but the devils are always in details. "MODULE" is defined when the target code (i.e. the sound core) is built as a module; but this doesn't mean that the caller is also built-in or not. Namely, when only the sound core is built-in (CONFIG_SND=y) while the driver is a module (CONFIG_SND_USB_AUDIO=m), the passed module pointer is ignored even if it's non-NULL, and card->module remains as NULL. This would result in the missing module reference up/down at the device open/close, leading to a race with the code execution after the module removal. For addressing the bug, move the assignment of card->module again out of ifdef. The WARN_ON() is still wrapped with ifdef because the module can be really NULL when all sound drivers are built-in. Note that we keep 'ifdef MODULE' for WARN_ON(), otherwise it would lead to a false-positive NULL module check. Admittedly it won't catch perfectly, i.e. no check is performed when CONFIG_SND=y. But, it's no real problem as it's only for debugging, and the condition is pretty rare.
Quoted source text, attributed separately from HOL analysis.