CVE-2025-40097
Brak sprawdzenia wskaźnika w funkcji hda_component_manager_init w jądrze Linuxa może prowadzić do awarii.
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_component_manager_init function The __component_match_add function may assign the 'matchptr' pointer the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced. The call stack leading to the error looks like this: hda_component_manager_init |-> component_match_add |-> component_match_add_release |-> __component_match_add ( ... ,**matchptr, ... ) |-> *matchptr = ERR_PTR(-ENOMEM); // assign |-> component_master_add_with_match( ... match) |-> component_match_realloc(match, match->num); // dereference Add IS_ERR() check to prevent the crash. Found by Linux Verification Center (linuxtesting.org) with SVACE.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-30 10:15:34 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:33 UTC |
- https://git.kernel.org/stable/c/1c3f4b15eb1850558d7d4da74b98cffbb8121721 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/1cf11d80db5df805b538c942269e05a65bcaf5bc (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/218a8504e62fc2c8a1fd12523346b7a2b9bd2474 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/47d1b9ca923b55c3f407788f1f15b04957e0e027 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/b044aa6ae63391ba40c93ca5d476d276cb17db1b (416baaa9-dc9f-4396-8d5f-8c081fb06d67)