cbcvebase.
CVE-2025-40013
published 2025-10-20

CVE-2025-40013: In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: audioreach: fix potential null pointer dereference It is possible that the…

PriorityP420high7.8
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: audioreach: fix potential null pointer dereference It is possible that the topology parsing function audioreach_widget_load_module_common() could return NULL or an error pointer. Add missing NULL check so that we do not dereference it.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 36ad9bf1d93d66b901342eab9f8ed6c1537655a6 < 9c1ad4192f3d2fc85339718a6252cb3337848f7b9c1ad4192f3d2fc85339718a6252cb3337848f7b
linuxlinux>= 36ad9bf1d93d66b901342eab9f8ed6c1537655a6 < 70e1e5fe9f7e05ff831b56ebc02543e7811b8e1870e1e5fe9f7e05ff831b56ebc02543e7811b8e18
linuxlinux>= 36ad9bf1d93d66b901342eab9f8ed6c1537655a6 < 4dda55d04caac3b4102c26e29b1c27fa35636be34dda55d04caac3b4102c26e29b1c27fa35636be3
linuxlinux>= 36ad9bf1d93d66b901342eab9f8ed6c1537655a6 < 8f9c9fafc0e7a73bbff58954d171c016ddee17348f9c9fafc0e7a73bbff58954d171c016ddee1734
linuxlinux>= 36ad9bf1d93d66b901342eab9f8ed6c1537655a6 < ef08ce6304d30b5778035d07b04514cb70839983ef08ce6304d30b5778035d07b04514cb70839983
linuxlinux>= 36ad9bf1d93d66b901342eab9f8ed6c1537655a6 < 8318e04ab2526b155773313b66a1542476ce11068318e04ab2526b155773313b66a1542476ce1106
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.11-16.16.11-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 5.16.0 < 6.1.1566.1.156
linuxlinux_kernel>= 6.13.0 < 6.16.116.16.11
linuxlinux_kernel>= 6.17.0 < 6.17.16.17.1
linuxlinux_kernel>= 6.2.0 < 6.6.1106.6.110
linuxlinux_kernel>= 6.7.0 < 6.12.516.12.51
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.