In the Linux kernel, the following vulnerability has been resolved:
soundwire: fix enumeration completion
The soundwire subsystem uses two completion structures that allow drivers to wait for soundwire device to become enumerated on the bus and initialised by their drivers, respectively.
The code implementing the signalling is currently broken as it does not signal all current and future waiters and also uses the wrong reinitialisation function, which can potentially lead to memory corruption if there are still waiters on the queue.
Not signalling future waiters specifically breaks sound card probe deferrals as codec drivers can not tell that the soundwire device is already attached when being reprobed. Some codec runtime PM implementations suffer from similar problems as waiting for enumeration during resume can also timeout despite the device already having been enumerated.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 29, 2025 | Dec 29, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 24, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotg-5.15Upgrade linux-bluefieldUpgrade linux-realtimeUpgrade linux-riscv-5.15Upgrade linux-intel-iotgUpgrade linux-lowlatency-hwe-5.15Upgrade linux-nvidia-tegra-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-kvmUpgrade linux-gcp-5.15Upgrade linux-nvidia-tegra-igxUpgrade linux-nvidia-tegraUpgrade linux-ibm-5.15Upgrade linux-gcpUpgrade linux-awsUpgrade linux-azureUpgrade linuxUpgrade linux-hwe-5.15Upgrade linux-oracleUpgrade linux-lowlatencyUpgrade linux-aws-5.15Upgrade linux-gkeUpgrade linux-gkeopUpgrade linux-nvidiaUpgrade linux-xilinx-zynqmpUpgrade linux-oracle-5.15Upgrade linux-azure-5.15Upgrade linux-raspiUpgrade linux-ibm | Jan 6, 2026 | Dec 24, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub