CVE-2025-40338

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
09/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ASoC: Intel: avs: Do not share the name pointer between components<br /> <br /> By sharing &amp;#39;name&amp;#39; directly, tearing down components may lead to<br /> use-after-free errors. Duplicate the name to avoid that.<br /> <br /> At the same time, update the order of operations - since commit<br /> cee28113db17 ("ASoC: dmaengine_pcm: Allow passing component name via<br /> config") the framework does not override component-&gt;name if set before<br /> invoking the initializer.

Impact