CVE-2024-27057
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-27057 affects the Linux kernel's ASoC (ALSA System on Chip) Sound Open Firmware (SOF) component, specifically related to the IPC4 PCM handling during system suspend operations. The vulnerability was discovered and disclosed on May 1, 2024, impacting systems using the Linux kernel with SOF audio drivers (NVD).

Technical details

The vulnerability occurs when the system is suspended while audio is active, triggering sof_ipc4_pcm_hw_free() to reset the pipelines. If the firmware crashes during audio operation or stream reset before suspend, the sof_ipc4_set_multi_pipeline_state() fails with an IPC error, interrupting the state change. This creates a state misalignment between the kernel and firmware on the next DSP boot, causing IPC message errors and audio resume failures (Kernel Commit).

Impact

The vulnerability results in audio functionality issues after system resume, specifically causing errors in IPC messages and failing audio resume operations. The system requires a second boot after DSP panic to correct the kernel state (Kernel Commit).

Mitigation and workarounds

A fix has been implemented that treats forced pipeline reset similarly to PCM free by ignoring error on state sending, allowing the kernel's state to maintain consistency with the firmware state after the next boot. The patch specifically handles cases where sof_ipc4_trigger_pipelines() is called from sof_ipc4_pcm_hw_free() with SOF_IPC4_PIPE_RESET state (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74726NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules
NoYesAug 22, 2026
CVE-2026-74719NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-partner
NoYesAug 22, 2026
CVE-2026-74717NONEN/A
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management