Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A NULL pointer dereference vulnerability has been identified in the Linux kernel's ASoC SOF Intel component, specifically in the Coffee Lake (cnl) platform. This issue arises when a firmware response is sent before the FW_READY message is received. The vulnerability occurs because the reply data is only allocated after the FW_READY message, leading to a potential NULL pointer dereference if the response is not properly filtered. While this issue was reported with IPC4 firmware, the same condition exists with IPC3.
Exploitation of this vulnerability leads to a NULL pointer dereference, causing a crash or unintended behavior in the system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.