CVE-2023-52692: ALSA: scarlett2: Add missing error check to scarlett2_usb_set_config()

Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: scarlett2: Add missing error check to scarlett2_usb_set_config()

scarlett2_usb_set_config() calls scarlett2_usb_get() but was not
checking the result. Return the error if it fails rather than
continuing with an invalid value.

Classification

CVE ID: CVE-2023-52692

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://git.kernel.org/stable/c/51d5697e1c0380d482c3eab002bfc8d0be177e99
https://git.kernel.org/stable/c/be96acd3eaa790d10a5b33e65267f52d02f6ad88
https://git.kernel.org/stable/c/996fde492ad9b9563ee483b363af40d7696a8467
https://git.kernel.org/stable/c/145c5aa51486171025ab47f35cff34bff8d0cea3
https://git.kernel.org/stable/c/ca459dfa7d4ed9098fcf13e410963be6ae9b6bf3

Timeline