CVE-2025-71192

Source
https://cve.org/CVERecord?id=CVE-2025-71192
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71192.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71192
Downstream
Related
Published
2026-02-04T16:00:23.044Z
Modified
2026-03-24T08:59:24.935673Z
Summary
ALSA: ac97: fix a double free in snd_ac97_controller_register()
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: ac97: fix a double free in sndac97controller_register()

If ac97addadapter() fails, putdevice() is the correct way to drop the device reference. kfree() is not required. Add kfree() if idralloc() fails and in ac97adapterrelease() to do the cleanup.

Found by code review.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71192.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
74426fbff66eea8e8d1f42c8238c268d1e63a832
Fixed
c80f9b3349a99a9d5b295f5bbc23f544c5995ad7
Fixed
21f8bc5179bed91c3f946adb5e55d717b891960c
Fixed
fcc04c92cbb5497ce67c58dd2f0001bb87f40396
Fixed
cb73d37ac18bc1716690ff5255a0ef1952827e9e
Fixed
830988b6cf197e6dcffdfe2008c5738e6c6c3c0f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71192.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
6.1.161
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.121
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.66
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71192.json"