In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: avs: Verify content returned by parseintarray()
The first element of the returned array stores its length. If it is 0, any manipulation beyond the element at index 0 ends with null-ptr-deref.
[
{
"id": "CVE-2025-38307-071a73e3",
"signature_type": "Function",
"digest": {
"length": 549.0,
"function_hash": "112978844208986876096168929568698809266"
},
"target": {
"file": "sound/soc/intel/avs/debugfs.c",
"function": "trace_control_write"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@18ff538aac63de1866e5a49d57e22788b5c21d12",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2025-38307-0f5d61c4",
"signature_type": "Line",
"digest": {
"line_hashes": [
"286548733405363535297353228349803980569",
"248470209331121607478508964606452117634",
"38485493409141848564345575521658427977",
"252472111840109059526140049946095317365"
],
"threshold": 0.9
},
"target": {
"file": "sound/soc/intel/avs/debugfs.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@18ff538aac63de1866e5a49d57e22788b5c21d12",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2025-38307-2bad1710",
"signature_type": "Function",
"digest": {
"length": 549.0,
"function_hash": "112978844208986876096168929568698809266"
},
"target": {
"file": "sound/soc/intel/avs/debugfs.c",
"function": "trace_control_write"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@93e246b6769bdacb09cfff4ea0f00fe5ab4f0d7a",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2025-38307-602d6b1d",
"signature_type": "Line",
"digest": {
"line_hashes": [
"286548733405363535297353228349803980569",
"248470209331121607478508964606452117634",
"38485493409141848564345575521658427977",
"252472111840109059526140049946095317365"
],
"threshold": 0.9
},
"target": {
"file": "sound/soc/intel/avs/debugfs.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@93e246b6769bdacb09cfff4ea0f00fe5ab4f0d7a",
"signature_version": "v1",
"deprecated": false
}
]