Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21847— ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查cstream空值,可能导致空指针取消引用。

AI Predicted 4.4 Difficulty: Moderate EPSS 0.21% · P12

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 11

VendorProduct Version RangeStatus
Linux Linux e46f81541b1bf5db45a8c7a9cbc35ffc696877dc< dfe25c554daa12ee26eb3540bbded57733ed5d9c affected
090349a9feba3ceee3997d31d68ffe54e5b57acb< 2b3878baf90918a361a3dfd3513025100b1b40b6 affected
090349a9feba3ceee3997d31d68ffe54e5b57acb< 62ab1ae5511c59b5f0bf550136ff321331adca9f affected
090349a9feba3ceee3997d31d68ffe54e5b57acb< 6c18f5eb2043ebf4674c08a9690218dc818a11ab affected
090349a9feba3ceee3997d31d68ffe54e5b57acb< d8d99c3b5c485f339864aeaa29f76269cc0ea975 affected
6.3 affected
< 6.3 unaffected
6.6.80≤ 6.6.* unaffected
… +3 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-21847

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data() The nullity of sps->cstream should be checked similarly as it is done in sof_set_stream_data_offset() function. Assuming that it is not NULL if sps->stream is NULL is incorrect and can lead to NULL pointer dereference.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查cstream空值,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e46f81541b1bf5db45a8c7a9cbc35ffc696877dc ~ dfe25c554daa12ee26eb3540bbded57733ed5d9c -
Linux Linux 6.3 -

II. Public POCs for CVE-2025-21847

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21847

登录查看更多情报信息。

Patches & Fixes for CVE-2025-21847 (1)

Other References for CVE-2025-21847 (4)

Same Patch Batch · Linux · 2025-03-12 · 26 CVEs total

CVE-2024-58087 9.8 CRITICAL ksmbd: fix racy issue from session lookup and expire
CVE-2025-21850 9.8 CRITICAL nvmet: Fix crash when a namespace is disabled
CVE-2025-21855 8.6 HIGH ibmvnic: Don't reference skb after sending to VIOS
CVE-2024-58089 7.8 HIGH btrfs: fix double accounting race when btrfs_run_delalloc_range() failed
CVE-2025-21858 7.8 HIGH geneve: Fix use-after-free in geneve_find_dev().
CVE-2025-21851 7.8 HIGH bpf: Fix softlockup in arena_map_free on 64k page kernel
CVE-2025-21864 7.8 HIGH tcp: drop secpath at the same time as we currently drop dst
CVE-2025-21844 7.5 HIGH smb: client: Add check for next_buffer in receive_encrypted_standard()
CVE-2025-21852 net: Add rx_skb of kfree_skb to raw_tp_null_args[].
CVE-2025-21865 gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().
CVE-2024-58088 bpf: Fix deadlock when freeing cgroup storage
CVE-2025-21845 mtd: spi-nor: sst: Fix SST write failure
CVE-2025-21846 acct: perform last write from workqueue
CVE-2025-21848 nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
CVE-2025-21849 drm/i915/gt: Use spin_lock_irqsave() in interruptible context
CVE-2025-21863 io_uring: prevent opcode speculation
CVE-2025-21853 bpf: avoid holding freeze_mutex during mmap operation
CVE-2025-21866 powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC
CVE-2025-21854 sockmap, vsock: For connectible sockets allow only connected
CVE-2025-21856 s390/ism: add release function for struct device

Showing top 20 of 26 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-21847

No comments yet


Leave a comment