Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-39892— ASoC: soc-core: care NULL dirver name on snd_soc_lookup_component_nolocked()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查NULL驱动程序名称,可能导致空指针取消引用。

AI Predicted 4.4 Difficulty: Hard EPSS 0.12% · P2

Possible ATT&CK Techniques 1 AI

T1499.003 · Application Exhaustion Flood

Affected Version Matrix 6

VendorProduct Version RangeStatus
Linux Linux 144d6dfc7482455eabf8e8caa974a6e8d9572705< 1d282dcd46d972be338085ae9e217462b366ce6e affected
144d6dfc7482455eabf8e8caa974a6e8d9572705< 168873ca1799d3f23442b9e79eae55f907b9b126 affected
6.16 affected
< 6.16 unaffected
6.16.6≤ 6.16.* unaffected
6.17≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-39892

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASoC: soc-core: care NULL dirver name on snd_soc_lookup_component_nolocked()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lookup_component_nolocked() soc-generic-dmaengine-pcm.c uses same dev for both CPU and Platform. In such case, CPU component driver might not have driver->name, then snd_soc_lookup_component_nolocked() will be NULL pointer access error. Care NULL driver name. Call trace: strcmp from snd_soc_lookup_component_nolocked+0x64/0xa4 snd_soc_lookup_component_nolocked from snd_soc_unregister_component_by_driver+0x2c/0x44 snd_soc_unregister_component_by_driver from snd_dmaengine_pcm_unregister+0x28/0x64 snd_dmaengine_pcm_unregister from devres_release_all+0x98/0xfc devres_release_all from device_unbind_cleanup+0xc/0x60 device_unbind_cleanup from really_probe+0x220/0x2c8 really_probe from __driver_probe_device+0x88/0x1a0 __driver_probe_device from driver_probe_device+0x30/0x110 driver_probe_device from __driver_attach+0x90/0x178 __driver_attach from bus_for_each_dev+0x7c/0xcc bus_for_each_dev from bus_add_driver+0xcc/0x1ec bus_add_driver from driver_register+0x80/0x11c driver_register from do_one_initcall+0x58/0x23c do_one_initcall from kernel_init_freeable+0x198/0x1f4 kernel_init_freeable from kernel_init+0x1c/0x12c kernel_init from ret_from_fork+0x14/0x28
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查NULL驱动程序名称,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 144d6dfc7482455eabf8e8caa974a6e8d9572705 ~ 1d282dcd46d972be338085ae9e217462b366ce6e -
Linux Linux 6.16 -

II. Public POCs for CVE-2025-39892

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-39892

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-10-01 · 169 CVEs total

CVE-2023-53517 9.8 CRITICAL tipc: do not update mtu if msg_max is too small in mtu negotiation
CVE-2025-39919 8.8 HIGH wifi: mt76: mt7996: add missing check for rx wcid entries
CVE-2025-39918 8.8 HIGH wifi: mt76: fix linked list corruption
CVE-2023-53454 8.8 HIGH HID: multitouch: Correct devm device reference for hidinput input_dev name
CVE-2022-50442 8.4 HIGH fs/ntfs3: Validate buffer length while parsing index
CVE-2023-53493 8.4 HIGH accel/qaic: tighten bounds checking in decode_message()
CVE-2023-53492 7.8 HIGH netfilter: nf_tables: do not ignore genmask when looking up chain by id
CVE-2025-39924 7.8 HIGH erofs: fix invalid algorithm for encoded extents
CVE-2023-53510 7.8 HIGH scsi: ufs: core: Fix handling of lrbp->cmd
CVE-2025-39927 7.8 HIGH ceph: fix race condition validating r_parent before applying state
CVE-2022-50421 7.8 HIGH rpmsg: char: Avoid double destroy of default endpoint
CVE-2023-53506 7.8 HIGH udf: Do not bother merging very long extents
CVE-2022-50423 7.8 HIGH ACPICA: Fix use-after-free in acpi_ut_copy_ipackage_to_ipackage()
CVE-2023-53504 7.8 HIGH RDMA/bnxt_re: Properly order ib_device_unalloc() to avoid UAF
CVE-2023-53495 7.8 HIGH net: ethernet: mvpp2_main: fix possible OOB write in mvpp2_ethtool_get_rxnfc()
CVE-2023-53494 7.8 HIGH crypto: xts - Handle EBUSY correctly
CVE-2022-50437 7.8 HIGH drm/msm/hdmi: fix memory corruption with too many bridges
CVE-2023-53478 7.8 HIGH tracing/synthetic: Fix races on freeing last_cmd
CVE-2023-53481 7.8 HIGH ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed
CVE-2023-53486 7.8 HIGH fs/ntfs3: Enhance the attribute size check

Showing top 20 of 169 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-39892

No comments yet


Leave a comment