CVE-2025-40045

high

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd937x: set the comp soundwire port correctly For some reason we endup with setting soundwire port for HPHL_COMP and HPHR_COMP as zero, this can potentially result in a memory corruption due to accessing and setting -1 th element of port_map array.

References

https://git.kernel.org/stable/c/abcd537aae3b84c6d10ad147e99a204bcb56b234

https://git.kernel.org/stable/c/66a940b1bf48a7095162688332d725ba160154eb

https://git.kernel.org/stable/c/1a1ca38392e7e896075afc8905ddaea525ed30f7

Details

Source: Mitre, NVD

Published: 2025-10-28

Updated: 2025-10-30

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00017