CVE-2025-40338
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
09/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ASoC: Intel: avs: Do not share the name pointer between components<br />
<br />
By sharing &#39;name&#39; directly, tearing down components may lead to<br />
use-after-free errors. Duplicate the name to avoid that.<br />
<br />
At the same time, update the order of operations - since commit<br />
cee28113db17 ("ASoC: dmaengine_pcm: Allow passing component name via<br />
config") the framework does not override component->name if set before<br />
invoking the initializer.



