CVE-2025-38438

Source
https://cve.org/CVERecord?id=CVE-2025-38438
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38438.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38438
Downstream
Related
Published
2025-07-25T15:27:17.917Z
Modified
2026-03-12T02:16:29.092681Z
Summary
ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak.
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak.

sofpdata->tplgfilename can have address allocated by kstrdup() and can be overwritten. Memory leak was detected with kmemleak:

unreferenced object 0xffff88812391ff60 (size 16): comm "kworker/4:1", pid 161, jiffies 4294802931 hex dump (first 16 bytes): 73 6f 66 2d 68 64 61 2d 67 65 6e 65 72 69 63 00 sof-hda-generic. backtrace (crc 4bf1675c): _kmallocnodetrackcallernoprof+0x49c/0x6b0 kstrdup+0x46/0xc0 hdamachineselect.cold+0x1de/0x12cf [sndsofintelhdageneric] sofinitenvironment+0x16f/0xb50 [sndsof] sofprobecontinue+0x45/0x7c0 [sndsof] sofprobework+0x1e/0x40 [sndsof] processonework+0x894/0x14b0 workerthread+0x5e5/0xfb0 kthread+0x39d/0x760 retfromfork+0x31/0x70 retfromforkasm+0x1a/0x30

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38438.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dd96daca6c83ecaf37f38ff49d8d174bbff576b4
Fixed
68397fda2caa90e99a7c0bcb2cf604e42ef3b91f
Fixed
58ecf51af12cb32b890858b52b2c34e80590c74a
Fixed
6c038b58a2dc5a008c7e7a1297f5aaa4deaaaa7e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38438.json"