In the Linux kernel, the following vulnerability has been resolved:
ASoC: soc-compress: prevent the potentially use of null pointer
There is one call trace that snd_soc_register_card() ->snd_soc_bind_card()->soc_init_pcm_runtime() ->snd_soc_dai_compress_new()->snd_soc_new_compress(). In the trace the 'codec_dai' transfers from card->dai_link, and we can see from the snd_soc_add_pcm_runtime() in snd_soc_bind_card() that, if value of card->dai_link->num_codecs is 0, then 'codec_dai' could be null pointer caused by index out of bound in 'asoc_rtd_to_codec(rtd, 0)'. And snd_soc_register_card() is called by various platforms. Therefore, it is better to add the check in the case of misusing. And because 'cpu_dai' has already checked in soc_init_pcm_runtime(), there is no need to check again. Adding the check as follow, then if 'codec_dai' is null, snd_soc_new_compress() will not pass through the check 'if (playback + capture != 1)', avoiding the leftover use of 'codec_dai'.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-toolsUpgrade kernel-livepatch-5.10.112-108.499Upgrade perfUpgrade kernel-develUpgrade bpftool-debuginfoUpgrade python-perfUpgrade kernel-debuginfo-common-aarch64Upgrade bpftoolUpgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfoUpgrade kernelUpgrade perf-debuginfoUpgrade kernel-debuginfoUpgrade kernel-headersUpgrade kernel-tools-develUpgrade kernel-tools-debuginfo | Mar 14, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-perfUpgrade kernel-abi-stablelistsUpgrade kernelUpgrade bpftoolUpgrade kernel-toolsUpgrade kernel-tools-libs | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-fipsUpgrade linux-realtimeUpgrade linux-oracle-5.4Upgrade linux-azure-5.15Upgrade linux-gcpUpgrade linux-azure-fipsUpgrade linux-ibmUpgrade linux-oracleUpgrade linux-intel-iotgUpgrade linux-kvmUpgrade linux-aws-5.4Upgrade linux-raspiUpgrade linux-aws-fipsUpgrade linux-gkeUpgrade linux-lowlatencyUpgrade linux-iotUpgrade linux-ibm-5.4Upgrade linux-gcp-fipsUpgrade linux-raspi-5.4Upgrade linux-gcp-5.4Upgrade linuxUpgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-intel-iotg-5.15Upgrade linux-bluefieldUpgrade linux-lowlatency-hwe-5.15Upgrade linux-azureUpgrade linux-hwe-5.4Upgrade linux-azure-5.4 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub