Junglewise Threat Intelligence

CVE-2025-38706: Linux Kernel NULL pointer dereference in ASoC core

CVE-2025-38706 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's audio subsystem could allow a local user to cause a system crash. The issue occurs when the system attempts to remove certain audio components that were previously ignored due to missing hardware. This results in a 'null pointer dereference,' leading to a kernel panic and a total loss of system availability.

Technical details

A NULL pointer dereference exists in the snd_soc_remove_pcm_runtime() function within the Linux kernel's ASoC core. The vulnerability is triggered when soc_tplg_remove_link() calls snd_soc_remove_pcm_runtime() with a NULL runtime (rtd) pointer, which occurs if a link was previously marked as ignored during topology loading (e.g., due to missing hardware). An attacker with local access could potentially trigger this condition during module removal, resulting in a kernel oops or panic (Denial of Service). The fix introduces a NULL check for the rtd pointer at the beginning of the affected function.

Affected products

  • Linux Linux Kernel 5.6 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-06-19: patched: Initial patch submitted to the Linux kernel tree.
  • 2025-09-04: disclosed: CVE-2025-38706 published.

References

Related threats