In the Linux kernel, the following vulnerability has been resolved:
ASoC: simple-card-utils: Don't use _free(devicenode) at graphutilparse_dai()
commit 419d1918105e ("ASoC: simple-card-utils: use _free(devicenode) for device node") uses _free(devicenode) for dlc->of_node, but we need to keep it while driver is in use.
Don't use _free(devicenode) in graphutilparse_dai().
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de74ec718e0788e1998eb7289ad07970e27cae27",
"id": "CVE-2025-39930-2c868f35",
"digest": {
"threshold": 0.9,
"line_hashes": [
"203659341968011796995076342901577732613",
"275382404918211058029437896951183328347",
"183697975912185031997128812540996899535",
"309560533089539532232705822410232119763",
"151939212630900518902499435595925386206",
"104604605432492472535271068587938135088",
"87520038005524638559433820208983230158",
"80600060169160217465695972688890269073",
"86082273115384842849260165035252600435",
"138951274179077605603439917698884814736",
"187912425415983070281239485242307867083",
"90571366938954712537815524996314315423",
"111783172635376687238265858017435989607"
]
},
"target": {
"file": "sound/soc/generic/simple-card-utils.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@232a32e8a7e9be8a2ee238df9b5304eed2f4e195",
"id": "CVE-2025-39930-746ec221",
"digest": {
"function_hash": "87312729067365196815675417804139994230",
"length": 718.0
},
"target": {
"function": "graph_util_parse_dai",
"file": "sound/soc/generic/simple-card-utils.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@232a32e8a7e9be8a2ee238df9b5304eed2f4e195",
"id": "CVE-2025-39930-b723cf32",
"digest": {
"threshold": 0.9,
"line_hashes": [
"203659341968011796995076342901577732613",
"275382404918211058029437896951183328347",
"183697975912185031997128812540996899535",
"309560533089539532232705822410232119763",
"151939212630900518902499435595925386206",
"104604605432492472535271068587938135088",
"87520038005524638559433820208983230158",
"80600060169160217465695972688890269073",
"86082273115384842849260165035252600435",
"138951274179077605603439917698884814736",
"187912425415983070281239485242307867083",
"90571366938954712537815524996314315423",
"111783172635376687238265858017435989607"
]
},
"target": {
"file": "sound/soc/generic/simple-card-utils.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@de74ec718e0788e1998eb7289ad07970e27cae27",
"id": "CVE-2025-39930-b9808c0d",
"digest": {
"function_hash": "87312729067365196815675417804139994230",
"length": 718.0
},
"target": {
"function": "graph_util_parse_dai",
"file": "sound/soc/generic/simple-card-utils.c"
},
"signature_type": "Function",
"signature_version": "v1"
}
]