CVE-2025-68205

Source
https://cve.org/CVERecord?id=CVE-2025-68205
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68205.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68205
Downstream
Published
2025-12-16T13:48:32.888Z
Modified
2025-12-16T20:23:38.841233Z
Summary
ALSA: hda/hdmi: Fix breakage at probing nvhdmi-mcp driver
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: hda/hdmi: Fix breakage at probing nvhdmi-mcp driver

After restructuring and splitting the HDMI codec driver code, each HDMI codec driver contains the own buildcontrols and buildpcms ops. A copy-n-paste error put the wrong entries for nvhdmi-mcp driver; both buildcontrols and buildpcms are swapped. Unfortunately both callbacks have the very same form, and the compiler didn't complain it, either. This resulted in a NULL dereference because the PCM instance hasn't been initialized at calling the build_controls callback.

Fix it by passing the proper entries.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68205.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ad781b550f9a8829e3dae4bd3d18c4a126a53d04
Fixed
d2aed6fac1148528181affb781aa683d6569042b
Fixed
82420bd4e17bdaba8453fbf9e10c58c9ed0c9727

Affected versions

v6.*
v6.16
v6.16-rc5
v6.16-rc6
v6.16-rc7
v6.17
v6.17-rc1
v6.17-rc2
v6.17-rc3
v6.17-rc4
v6.17-rc5
v6.17-rc6
v6.17-rc7
v6.17.1
v6.17.2
v6.17.3
v6.17.4
v6.17.5
v6.17.6
v6.17.7
v6.17.8
v6.18-rc1
v6.18-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68205.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.17.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68205.json"