CVE-2025-38307

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Verify content returned by parse_int_array() The first element of the returned array stores its length. If it is 0, any manipulation beyond the element at index 0 ends with null-ptr-deref.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

18 Nov 2025, 12:55

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/18ff538aac63de1866e5a49d57e22788b5c21d12 - () https://git.kernel.org/stable/c/18ff538aac63de1866e5a49d57e22788b5c21d12 - Patch
References () https://git.kernel.org/stable/c/2916794ffbce604cc2cda105f6b8a4a7c748dd7f - () https://git.kernel.org/stable/c/2916794ffbce604cc2cda105f6b8a4a7c748dd7f - Patch
References () https://git.kernel.org/stable/c/93e246b6769bdacb09cfff4ea0f00fe5ab4f0d7a - () https://git.kernel.org/stable/c/93e246b6769bdacb09cfff4ea0f00fe5ab4f0d7a - Patch
References () https://git.kernel.org/stable/c/cc03c899e6d9812b25c3754c9a95c3830c4aec26 - () https://git.kernel.org/stable/c/cc03c899e6d9812b25c3754c9a95c3830c4aec26 - Patch

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ASoC: Intel: avs: Verificar el contenido devuelto por parse_int_array(). El primer elemento de la matriz devuelta almacena su longitud. Si es 0, cualquier manipulación más allá del elemento en el índice 0 termina con null-ptr-deref.

10 Jul 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 08:15

Updated : 2025-11-18 12:55


NVD link : CVE-2025-38307

Mitre link : CVE-2025-38307

CVE.ORG link : CVE-2025-38307


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference