In the Linux kernel, the following vulnerability has been resolved:
ASoC: rt711-sdca: fix kernel NULL pointer dereference when IO error
The initial settings will be written before the codec probe function. But, the rt711->component doesn't be assigned yet. If IO error happened during initial settings operations, it will cause the kernel panic. This patch changed component->dev to slave->dev to fix this issue.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-aws-5.15Upgrade linux-riscv-5.15Upgrade linux-oracle-5.15Upgrade linux-gcpUpgrade linux-gkeUpgrade linux-intel-iotgUpgrade linux-lowlatency-hwe-5.15Upgrade linux-lowlatencyUpgrade linux-raspiUpgrade linuxUpgrade linux-nvidiaUpgrade linux-ibmUpgrade linux-kvmUpgrade linux-gkeopUpgrade linux-realtimeUpgrade linux-azure-5.15Upgrade linux-gcp-5.15Upgrade linux-oracleUpgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-hwe-5.15Upgrade linux-azure-fde-5.15Upgrade linux-aws | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub