CVE-2024-58077 affects the Linux kernel ALSA System-on-Chip (ASoC) PCM implementation in sound/soc/soc-pcm.c. The .prepare callback incorrectly used the shared soc_pcm_ret() error handler, which broadly suppresses -EINVAL errors. That suppression was intended to stop user-controlled invalid audio parameters from generating excessive syslog output and consuming disk space, but was inappropriate in the callback and could enable a local denial of service through uncontrolled resource consumption.
Upstream Linux fixes remove soc_pcm_ret() from the .prepare path and are available in kernel versions 6.1.129, 6.6.78, 6.12.14, 6.13.3, and 6.14-rc1 and later. Red Hat rated the issue 4.4/10 due to required local, high-privilege access and availability impact, while NVD assigned 5.5/10; fixes were released for RHEL 9 and RHEL 10 through RHSA-2025:20518 and RHSA-2025:20095, respectively, while the RHEL 9 kernel-rt fix remained deferred.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9, providing kernel fixes for CVE-2024-58077. RHEL 9 kernel-rt remained fix-deferred.
The Linux kernel CVE team announced CVE-2024-58077 in ALSA ASoC PCM code, where the .prepare callback's use of soc_pcm_ret() could improperly suppress -EINVAL errors. The upstream remediation removes soc_pcm_ret() from that callback; fixes were identified in kernel versions 6.1.129, 6.6.78, 6.12.14, 6.13.3, and 6.14-rc1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.