Home

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when closing PCM avs_dai_fe_shutdown() handles the shutdown procedure for HOST HDAudio stream while period-elapsed work services its IRQs. As the former frees the DAI's private context, these two operations shall be synchronized to avoid slab-use-after-free or worse errors.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-09 | Updated 2025-12-09 | Assigner Linux

Product status

Default status
unaffected

0dbb186c3510cad4e9f443e801bf2e6ab5770c00 (git) before ca6d2b7aca778afbf8c0c4b330d10cb228c14052
affected

0dbb186c3510cad4e9f443e801bf2e6ab5770c00 (git) before b41fca4aa60be896ba8a81b57aac5dcc6eee66c0
affected

0dbb186c3510cad4e9f443e801bf2e6ab5770c00 (git) before 845f716dc5f354c719f6fda35048b6c2eca99331
affected

31087af37d6b1586b76d4acf3e0c1634a4617ba6 (git)
affected

Default status
affected

6.12
affected

Any version before 6.12
unaffected

6.12.58 (semver)
unaffected

6.17.8 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/ca6d2b7aca778afbf8c0c4b330d10cb228c14052

git.kernel.org/...c/b41fca4aa60be896ba8a81b57aac5dcc6eee66c0

git.kernel.org/...c/845f716dc5f354c719f6fda35048b6c2eca99331

cve.org (CVE-2025-40344)

nvd.nist.gov (CVE-2025-40344)

Download JSON