CVE Database
/

CVE-2024-39491

Back to search

CVE-2024-39491

Published: Jul 10, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance The cs_dsp instance is initialized in the driver probe() so it should be freed in the driver remove(). Also fix a missing call to cs_dsp_remove() in the error path of cs35l56_hda_common_probe(). The call to cs_dsp_remove() was being done in the component unbind callback cs35l56_hda_unbind(). This meant that if the driver was unbound and then re-bound it would be using an uninitialized cs_dsp instance. It is best to initialize the cs_dsp instance in probe() so that it can return an error if it fails. The component binding API doesn't have any error handling so there's no way to handle a failure if cs_dsp was initialized in the bind.

VendorProductVersions

Linux

Linux

affected
73cfbfa9caea8eda54b4c6e49a9555533660aa1e - < 9054c474f9c219e58a441e401c0e6e38fe713ff1
affected
73cfbfa9caea8eda54b4c6e49a9555533660aa1e - < 60d5e087e5f334475b032ad7e6ad849fb998f303
affected
73cfbfa9caea8eda54b4c6e49a9555533660aa1e - < d344873c4cbde249b7152d36a273bcc45864001e

Linux

Linux

affected
6.6
unaffected
0 - < 6.6
unaffected
6.6.33 - <= 6.6.*
unaffected
6.9.4 - <= 6.9.*
unaffected
6.10 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now