CVE-2026-43137

Source
https://cve.org/CVERecord?id=CVE-2026-43137
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43137.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43137
Downstream
Published
2026-05-06T11:27:23.592Z
Modified
2026-06-18T03:55:01.139720547Z
Summary
ASoC: SOF: Intel: hda: Fix NULL pointer dereference
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: Intel: hda: Fix NULL pointer dereference

If there's a mismatch between the DAI links in the machine driver and the topology, it is possible that the playback/capture widget is not set, especially in the case of loopback capture for echo reference where we use the dummy DAI link. Return the error when the widget is not set to avoid a null pointer dereference like below when the topology is broken.

RIP: 0010:hdadaigetops.isra.0+0x14/0xa0 [sndsofintelhda_common]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43137.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0acb48dd31e39b617bb12ca546b4fecd6ccb2972
Fixed
a1d4f3d3c0dc86527da6a19f6901a6a48375500d
Fixed
10411f1f2c76be67103b1f95822ff629aa25e2aa
Fixed
42068f7dd42b559c4eeae645e1455ff36518866a
Fixed
7750d78b4014902bc0ac03d4bb30faa076a913ab
Fixed
16c589567a956d46a7c1363af3f64de3d420af20

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43137.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.75
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.16
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43137.json"