« Volver al listado

CVE-2025-40097

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: hda: Fix missing pointer check in hda_component_manager_init function

The __component_match_add function may assign the 'matchptr' pointer the value ERR_PTR(-ENOMEM), which will subsequently be dereferenced.

The call stack leading to the error looks like this:

Add IS_ERR() check to prevent the crash.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Detalles técnicos trazas, registros y código del informe original
hda_component_manager_init
|-> component_match_add
    |-> component_match_add_release
        |-> __component_match_add ( ... ,**matchptr, ... )
            |-> *matchptr = ERR_PTR(-ENOMEM);       // assign
|-> component_master_add_with_match( ...  match)
    |-> component_match_realloc(match, match->num); // dereference

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-40097",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ae7abe36e352eddf8e30d3b1ea3fb402514ba13b",
              "lessThan": "b044aa6ae63391ba40c93ca5d476d276cb17db1b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae7abe36e352eddf8e30d3b1ea3fb402514ba13b",
              "lessThan": "1c3f4b15eb1850558d7d4da74b98cffbb8121721",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae7abe36e352eddf8e30d3b1ea3fb402514ba13b",
              "lessThan": "218a8504e62fc2c8a1fd12523346b7a2b9bd2474",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae7abe36e352eddf8e30d3b1ea3fb402514ba13b",
              "lessThan": "47d1b9ca923b55c3f407788f1f15b04957e0e027",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae7abe36e352eddf8e30d3b1ea3fb402514ba13b",
              "lessThan": "1cf11d80db5df805b538c942269e05a65bcaf5bc",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/hda/codecs/side-codecs/hda_component.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.59",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.5",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/hda/codecs/side-codecs/hda_component.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-10-30T10:15:34.173",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1c3f4b15eb1850558d7d4da74b98cffbb8121721",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1cf11d80db5df805b538c942269e05a65bcaf5bc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/218a8504e62fc2c8a1fd12523346b7a2b9bd2474",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/47d1b9ca923b55c3f407788f1f15b04957e0e027",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b044aa6ae63391ba40c93ca5d476d276cb17db1b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: Fix missing pointer check in hda_component_manager_init function\n\nThe __component_match_add function may assign the 'matchptr' pointer\nthe value ERR_PTR(-ENOMEM), which will subsequently be dereferenced.\n\nThe call stack leading to the error looks like this:\n\nhda_component_manager_init\n|-> component_match_add\n    |-> component_match_add_release\n        |-> __component_match_add ( ... ,**matchptr, ... )\n            |-> *matchptr = ERR_PTR(-ENOMEM);       // assign\n|-> component_master_add_with_match( ...  match)\n    |-> component_match_realloc(match, match->num); // dereference\n\nAdd IS_ERR() check to prevent the crash.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
    }
  ],
  "lastModified": "2026-10-03T11:17:33.030",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}