Home

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Do not share the name pointer between components By sharing 'name' directly, tearing down components may lead to use-after-free errors. Duplicate the name to avoid that. At the same time, update the order of operations - since commit cee28113db17 ("ASoC: dmaengine_pcm: Allow passing component name via config") the framework does not override component->name if set before invoking the initializer.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-09 | Updated 2025-12-09 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 128bf29c992988f8b4f3829227339908fde5ec86
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 4dee5c1cc439b0d5ef87f741518268ad6a95b23d
affected

Default status
affected

6.17.8 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/128bf29c992988f8b4f3829227339908fde5ec86

git.kernel.org/...c/4dee5c1cc439b0d5ef87f741518268ad6a95b23d

cve.org (CVE-2025-40338)

nvd.nist.gov (CVE-2025-40338)

Download JSON