Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-38706

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
04/09/2025
Última modificación:
03/11/2025

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()<br /> <br /> snd_soc_remove_pcm_runtime() might be called with rtd == NULL which will<br /> leads to null pointer dereference.<br /> This was reproduced with topology loading and marking a link as ignore<br /> due to missing hardware component on the system.<br /> On module removal the soc_tplg_remove_link() would call<br /> snd_soc_remove_pcm_runtime() with rtd == NULL since the link was ignored,<br /> no runtime was created.

Impacto