CVE-2025-38706

Source
https://cve.org/CVERecord?id=CVE-2025-38706
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38706.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38706
Downstream
Related
Published
2025-09-04T15:32:57.456Z
Modified
2026-05-07T04:16:32.500926Z
Summary
ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: core: Check for rtd == NULL in sndsocremovepcmruntime()

sndsocremovepcmruntime() might be called with rtd == NULL which will leads to null pointer dereference. This was reproduced with topology loading and marking a link as ignore due to missing hardware component on the system. On module removal the soctplgremovelink() would call sndsocremovepcm_runtime() with rtd == NULL since the link was ignored, no runtime was created.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38706.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
50cd9b5317d5593d0a33f4227f56ddcc1bf66604
Fixed
8b465bedc2b417fd27c1d1ab7122882b4b60b1a0
Fixed
82ba7b8cf9f6e3bf392a9f08ba3d1c0b200ccb94
Fixed
7f8fc03712194fd4e2df28af7f7f7a38205934ef
Fixed
41f53afe53a57a7c50323f99424b598190acf192
Fixed
2fce20decc6a83f16dd73744150c4e7ea6c97c21
Fixed
cecc65827ef3df9754e097582d89569139e6cd1e
Fixed
7ce0a7255ce97ed7c54afae83fdbce712a1f0c9e
Fixed
2d91cb261cac6d885954b8f5da28b5c176c18131

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38706.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.10.241
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.190
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.149
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.103
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.43
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.11
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38706.json"