CVE-2025-38706

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() snd_soc_remove_pcm_runtime() might be called with rtd == NULL which will leads to null pointer dereference. This was reproduced with topology loading and marking a link as ignore due to missing hardware component on the system. On module removal the soc_tplg_remove_link() would call snd_soc_remove_pcm_runtime() with rtd == NULL since the link was ignored, no runtime was created.

References

https://git.kernel.org/stable/c/cecc65827ef3df9754e097582d89569139e6cd1e

https://git.kernel.org/stable/c/8b465bedc2b417fd27c1d1ab7122882b4b60b1a0

https://git.kernel.org/stable/c/82ba7b8cf9f6e3bf392a9f08ba3d1c0b200ccb94

https://git.kernel.org/stable/c/7f8fc03712194fd4e2df28af7f7f7a38205934ef

https://git.kernel.org/stable/c/7ce0a7255ce97ed7c54afae83fdbce712a1f0c9e

https://git.kernel.org/stable/c/41f53afe53a57a7c50323f99424b598190acf192

https://git.kernel.org/stable/c/2fce20decc6a83f16dd73744150c4e7ea6c97c21

https://git.kernel.org/stable/c/2d91cb261cac6d885954b8f5da28b5c176c18131

Details

Source: Mitre, NVD

Published: 2025-09-04

Updated: 2025-09-05

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00024