CVE-2025-38706

Source
https://cve.org/CVERecord?id=CVE-2025-38706
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38706.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38706
Downstream
Related
Published
2025-09-04T15:32:57.456Z
Modified
2026-03-12T02:16:28.384851Z
Summary
ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: core: Check for rtd == NULL in sndsocremovepcmruntime()

sndsocremovepcmruntime() might be called with rtd == NULL which will leads to null pointer dereference. This was reproduced with topology loading and marking a link as ignore due to missing hardware component on the system. On module removal the soctplgremovelink() would call sndsocremovepcm_runtime() with rtd == NULL since the link was ignored, no runtime was created.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38706.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
50cd9b5317d5593d0a33f4227f56ddcc1bf66604
Fixed
8b465bedc2b417fd27c1d1ab7122882b4b60b1a0
Fixed
82ba7b8cf9f6e3bf392a9f08ba3d1c0b200ccb94
Fixed
7f8fc03712194fd4e2df28af7f7f7a38205934ef
Fixed
41f53afe53a57a7c50323f99424b598190acf192
Fixed
2fce20decc6a83f16dd73744150c4e7ea6c97c21
Fixed
cecc65827ef3df9754e097582d89569139e6cd1e
Fixed
7ce0a7255ce97ed7c54afae83fdbce712a1f0c9e
Fixed
2d91cb261cac6d885954b8f5da28b5c176c18131

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38706.json"