{"id":"DEBIAN-CVE-2024-46849","details":"In the Linux kernel, the following vulnerability has been resolved:  ASoC: meson: axg-card: fix 'use-after-free'  Buffer 'card-\u003edai_link' is reallocated in 'meson_card_reallocate_links()', so move 'pad' pointer initialization after this function when memory is already reallocated.  Kasan bug report:  ================================================================== BUG: KASAN: slab-use-after-free in axg_card_add_link+0x76c/0x9bc Read of size 8 at addr ffff000000e8b260 by task modprobe/356  CPU: 0 PID: 356 Comm: modprobe Tainted: G O 6.9.12-sdkernel #1 Call trace:  dump_backtrace+0x94/0xec  show_stack+0x18/0x24  dump_stack_lvl+0x78/0x90  print_report+0xfc/0x5c0  kasan_report+0xb8/0xfc  __asan_load8+0x9c/0xb8  axg_card_add_link+0x76c/0x9bc [snd_soc_meson_axg_sound_card]  meson_card_probe+0x344/0x3b8 [snd_soc_meson_card_utils]  platform_probe+0x8c/0xf4  really_probe+0x110/0x39c  __driver_probe_device+0xb8/0x18c  driver_probe_device+0x108/0x1d8  __driver_attach+0xd0/0x25c  bus_for_each_dev+0xe0/0x154  driver_attach+0x34/0x44  bus_add_driver+0x134/0x294  driver_register+0xa8/0x1e8  __platform_driver_register+0x44/0x54  axg_card_pdrv_init+0x20/0x1000 [snd_soc_meson_axg_sound_card]  do_one_initcall+0xdc/0x25c  do_init_module+0x10c/0x334  load_module+0x24c4/0x26cc  init_module_from_file+0xd4/0x128  __arm64_sys_finit_module+0x1f4/0x41c  invoke_syscall+0x60/0x188  el0_svc_common.constprop.0+0x78/0x13c  do_el0_svc+0x30/0x40  el0_svc+0x38/0x78  el0t_64_sync_handler+0x100/0x12c  el0t_64_sync+0x190/0x194","modified":"2026-09-15T09:03:11.865520335Z","published":"2024-09-27T13:15:16.723Z","upstream":["CVE-2024-46849"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-46849"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.112-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46849.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46849.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46849.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}