CVE-2023-52988

Updated: 2025-10-05 01:40:58.977421

Description:

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path() snd_hda_get_connections() can return a negative error code. It may lead to accessing 'conn' array at a negative index. Found by Linux Verification Center (linuxtesting.org) with SVACE.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1747725447 2025-05-21 01:41:13
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1749568993 2025-06-11 00:59:24
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2025:1749562017 2025-06-11 04:00:03
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Already Fixed 2025-04-24 03:59:59
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2025:1747430034 2025-05-18 05:07:27
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Already Fixed 2025-04-25 03:48:57