In the Linux kernel, the following vulnerability has been resolved:
staging: greybus: audio_helper: remove unused and wrong debugfs usage
In the greybus audio_helper code, the debugfs file for the dapm has the potential to be removed and memory will be leaked. There is also the very real potential for this code to remove ALL debugfs entries from the system, and it seems like this is what will really happen if this code ever runs. This all is very wrong as the greybus audio driver did not create this debugfs file, the sound core did and controls the lifespan of it.
So remove all of the debugfs logic from the audio_helper code as there's no way it could be correct. If this really is needed, it can come back with a fixup for the incorrect usage of the debugfs_lookup() call which is what caused this to be noticed at all.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Sep 22, 2025 | Sep 22, 2025 |
| Ubuntu | — | Upgrade linux-azure-5.15Upgrade linux-raspiUpgrade linux-intel-iotg-5.15Upgrade linux-oracle-5.15Upgrade linuxUpgrade linux-gkeopUpgrade linux-hwe-5.15Upgrade linux-ibmUpgrade linux-azure-fde-5.15Upgrade linux-intel-iotgUpgrade linux-riscv-5.15Upgrade linux-lowlatencyUpgrade linux-nvidiaUpgrade linux-oracleUpgrade linux-kvmUpgrade linux-gkeUpgrade linux-realtimeUpgrade linux-aws-5.15Upgrade linux-gcpUpgrade linux-azureUpgrade linux-lowlatency-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-bluefieldUpgrade linux-aws | Sep 26, 2025 | Sep 18, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 15, 2025 | Sep 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub