In the Linux kernel, the following vulnerability has been resolved:
ASoC: rt711-sdca: fix kernel NULL pointer dereference when IO error
The initial settings will be written before the codec probe function. But, the rt711->component doesn't be assigned yet. If IO error happened during initial settings operations, it will cause the kernel panic. This patch changed component->dev to slave->dev to fix this issue.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-realtimeUpgrade linux-kvmUpgrade linux-intel-iotg-5.15Upgrade linux-azure-fde-5.15Upgrade linux-gcp-5.15Upgrade linux-nvidiaUpgrade linux-oracleUpgrade linux-ibmUpgrade linux-awsUpgrade linux-gkeopUpgrade linux-azure-5.15Upgrade linux-azureUpgrade linux-hwe-5.15Upgrade linux-gcpUpgrade linux-riscv-5.15Upgrade linux-gkeUpgrade linux-intel-iotgUpgrade linux-aws-5.15Upgrade linux-oracle-5.15Upgrade linuxUpgrade linux-raspiUpgrade linux-lowlatencyUpgrade linux-lowlatency-hwe-5.15 | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub