DEBIAN-CVE-2025-39892

Source
https://security-tracker.debian.org/tracker/CVE-2025-39892
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-39892.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-39892
Upstream
Published
2025-10-01T08:15:31.733Z
Modified
2026-04-28T20:30:07.755836Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on sndsoclookupcomponentnolocked() soc-generic-dmaengine-pcm.c uses same dev for both CPU and Platform. In such case, CPU component driver might not have driver->name, then sndsoclookupcomponentnolocked() will be NULL pointer access error. Care NULL driver name. Call trace: strcmp from sndsoclookupcomponentnolocked+0x64/0xa4 sndsoclookupcomponentnolocked from sndsocunregistercomponentbydriver+0x2c/0x44 sndsocunregistercomponentbydriver from snddmaenginepcmunregister+0x28/0x64 snddmaenginepcmunregister from devresreleaseall+0x98/0xfc devresreleaseall from deviceunbindcleanup+0xc/0x60 deviceunbindcleanup from reallyprobe+0x220/0x2c8 reallyprobe from __driverprobedevice+0x88/0x1a0 __driverprobedevice from driverprobedevice+0x30/0x110 driverprobedevice from __driver_attach+0x90/0x178 _driverattach from busforeachdev+0x7c/0xcc busforeachdev from busadddriver+0xcc/0x1ec busadddriver from driverregister+0x80/0x11c driverregister from dooneinitcall+0x58/0x23c dooneinitcall from kernelinitfreeable+0x198/0x1f4 kernelinitfreeable from kernelinit+0x1c/0x12c kernelinit from retfromfork+0x14/0x28

References

Affected packages

Debian:14 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.16.6-1

Affected versions

6.*
6.12.38-1
6.12.41-1
6.12.43-1~bpo12+1
6.12.43-1
6.12.48-1
6.12.57-1~bpo12+1
6.12.57-1
6.12.63-1~bpo12+1
6.12.63-1
6.12.69-1~bpo12+1
6.12.69-1
6.12.73-1~bpo12+1
6.12.73-1
6.12.74-1
6.12.74-2~bpo12+1
6.12.74-2
6.13~rc6-1~exp1
6.13~rc7-1~exp1
6.13.2-1~exp1
6.13.3-1~exp1
6.13.4-1~exp1
6.13.5-1~exp1
6.13.6-1~exp1
6.13.7-1~exp1
6.13.8-1~exp1
6.13.9-1~exp1
6.13.10-1~exp1
6.13.11-1~exp1
6.14.3-1~exp1
6.14.5-1~exp1
6.14.6-1~exp1
6.15~rc7-1~exp1
6.15-1~exp1
6.15.1-1~exp1
6.15.2-1~exp1
6.15.3-1~exp1
6.15.4-1~exp1
6.15.5-1~exp1
6.15.6-1~exp1
6.16~rc7-1~exp1
6.16-1~exp1
6.16.1-1~exp1
6.16.3-1~bpo13+1
6.16.3-1
6.16.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-39892.json"