CVE-2025-21847

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data() The nullity of sps->cstream should be checked similarly as it is done in sof_set_stream_data_offset() function. Assuming that it is not NULL if sps->stream is NULL is incorrect and can lead to NULL pointer dereference.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc3:*:*:*:*:*:*

History

13 Mar 2025, 16:28

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/2b3878baf90918a361a3dfd3513025100b1b40b6 - () https://git.kernel.org/stable/c/2b3878baf90918a361a3dfd3513025100b1b40b6 - Patch
References () https://git.kernel.org/stable/c/62ab1ae5511c59b5f0bf550136ff321331adca9f - () https://git.kernel.org/stable/c/62ab1ae5511c59b5f0bf550136ff321331adca9f - Patch
References () https://git.kernel.org/stable/c/6c18f5eb2043ebf4674c08a9690218dc818a11ab - () https://git.kernel.org/stable/c/6c18f5eb2043ebf4674c08a9690218dc818a11ab - Patch
References () https://git.kernel.org/stable/c/d8d99c3b5c485f339864aeaa29f76269cc0ea975 - () https://git.kernel.org/stable/c/d8d99c3b5c485f339864aeaa29f76269cc0ea975 - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ASoC: SOF: stream-ipc: Comprobación de nulidad de cstream en sof_ipc_msg_data(). La nulidad de sps->cstream debe comprobarse de forma similar a como se realiza en la función sof_set_stream_data_offset(). Asumir que no es NULL si sps->stream es NULL es incorrecto y puede provocar la desreferenciación del puntero NULL.
CPE cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

12 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 10:15

Updated : 2025-03-13 16:28


NVD link : CVE-2025-21847

Mitre link : CVE-2025-21847

CVE.ORG link : CVE-2025-21847


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference