CVE-2025-68345

Source
https://cve.org/CVERecord?id=CVE-2025-68345
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68345.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68345
Downstream
Related
Published
2025-12-24T10:32:38.378Z
Modified
2026-03-12T04:31:47.799752Z
Summary
ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi()
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41hdaread_acpi()

The acpigetfirstphysicalnode() function can return NULL, in which case the get_device() function also returns NULL, but this value is then dereferenced without checking,so add a check to prevent a crash.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68345.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7b2f3eb492dac7665c75df067e4d8e4869589f4a
Fixed
e63f9c81ca28b06eeeac3630faddc50717897351
Fixed
7a35a505d76a4b6cd426b59ff2d800d0394cc5d3
Fixed
e6ba921b17797ccc545d80e0dbccb5fab91c248c
Fixed
c28946b7409b7b68fb0481ec738c8b04578b11c6
Fixed
343fa9800cf9870ec681e21f0a6f2157b74ae520
Fixed
c34b04cc6178f33c08331568c7fd25c5b9a39f66

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68345.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.13
Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68345.json"