In the Linux kernel, the following vulnerability has been resolved:
ASoC: soc-compress: prevent the potentially use of null pointer
There is one call trace that snd_soc_register_card() ->snd_soc_bind_card()->soc_init_pcm_runtime() ->snd_soc_dai_compress_new()->snd_soc_new_compress(). In the trace the 'codec_dai' transfers from card->dai_link, and we can see from the snd_soc_add_pcm_runtime() in snd_soc_bind_card() that, if value of card->dai_link->num_codecs is 0, then 'codec_dai' could be null pointer caused by index out of bound in 'asoc_rtd_to_codec(rtd, 0)'. And snd_soc_register_card() is called by various platforms. Therefore, it is better to add the check in the case of misusing. And because 'cpu_dai' has already checked in soc_init_pcm_runtime(), there is no need to check again. Adding the check as follow, then if 'codec_dai' is null, snd_soc_new_compress() will not pass through the check 'if (playback + capture != 1)', avoiding the leftover use of 'codec_dai'.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade perf-debuginfoUpgrade kernel-tools-develUpgrade kernel-headersUpgrade kernel-debuginfoUpgrade kernelUpgrade kernel-tools-debuginfoUpgrade python-perf-debuginfoUpgrade bpftoolUpgrade kernel-develUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade python-perfUpgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade kernel-livepatch-5.10.112-108.499 | Mar 14, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-tools-libsUpgrade kernelUpgrade bpftoolUpgrade kernel-toolsUpgrade python3-perfUpgrade kernel-abi-stablelists | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linuxUpgrade linux-hwe-5.4Upgrade linux-gcp-fipsUpgrade linux-lowlatency-hwe-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-ibm-5.4Upgrade linux-hwe-5.15Upgrade linux-azure-5.4Upgrade linux-awsUpgrade linux-iotUpgrade linux-gcp-5.4Upgrade linux-bluefieldUpgrade linux-azureUpgrade linux-raspi-5.4Upgrade linux-aws-5.4Upgrade linux-oracle-5.4Upgrade linux-gkeUpgrade linux-fipsUpgrade linux-raspiUpgrade linux-gcpUpgrade linux-azure-5.15Upgrade linux-realtimeUpgrade linux-oracleUpgrade linux-kvmUpgrade linux-ibmUpgrade linux-intel-iotgUpgrade linux-lowlatencyUpgrade linux-azure-fipsUpgrade linux-aws-fips | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub