
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-27057 affects the Linux kernel's ASoC (ALSA System on Chip) Sound Open Firmware (SOF) component, specifically related to the IPC4 PCM handling during system suspend operations. The vulnerability was discovered and disclosed on May 1, 2024, impacting systems using the Linux kernel with SOF audio drivers (NVD).
The vulnerability occurs when the system is suspended while audio is active, triggering sof_ipc4_pcm_hw_free() to reset the pipelines. If the firmware crashes during audio operation or stream reset before suspend, the sof_ipc4_set_multi_pipeline_state() fails with an IPC error, interrupting the state change. This creates a state misalignment between the kernel and firmware on the next DSP boot, causing IPC message errors and audio resume failures (Kernel Commit).
The vulnerability results in audio functionality issues after system resume, specifically causing errors in IPC messages and failing audio resume operations. The system requires a second boot after DSP panic to correct the kernel state (Kernel Commit).
A fix has been implemented that treats forced pipeline reset similarly to PCM free by ignoring error on state sending, allowing the kernel's state to maintain consistency with the firmware state after the next boot. The patch specifically handles cases where sof_ipc4_trigger_pipelines() is called from sof_ipc4_pcm_hw_free() with SOF_IPC4_PIPE_RESET state (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."