CVE-2025-40085

Source
https://cve.org/CVERecord?id=CVE-2025-40085
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40085.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-40085
Downstream
Related
Published
2025-10-29T13:37:04.707Z
Modified
2026-03-23T05:32:01.239874Z
Summary
ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Fix NULL pointer deference in trytoregister_card

In trytoregistercard(), the return value of usbifnumtoif() is passed directly to usbinterfaceclaimed() without a NULL check, which will lead to a NULL pointer dereference when creating an invalid USB audio device. Fix this by adding a check to ensure the interface pointer is valid before passing it to usbinterfaceclaimed().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40085.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
28787ff9fbeaf57684eb64cc33e2ec8ceedf21b5
Fixed
736159f7b296d7a95f7208eb4799639b1f8b16a0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39efc9c8a973ddff5918191525d1679d0fb368ea
Fixed
8d19a7ab28c7b9c207db5c5282afa8cc8595bcdb
Fixed
576312eb436326b44b7010f4d9ae2b698df075ea
Fixed
bba7208765d26e5e36b87f21dacc2780b064f41f
Fixed
8503ac1a62075a085402e42a386b5c627c821a51
Fixed
28412b489b088fb88dff488305fd4e56bd47f6e4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
9d4f4dc3cd38e412c29a7626489fe48b79ebbf6c
Last affected
52076a41c128146c9df4a157e972cb17019313b1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40085.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.196
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.158
Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.6.114
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.12.55
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.17.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40085.json"