cbcvebase.
CVE-2025-40045
published 2025-10-28

CVE-2025-40045: In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd937x: set the comp soundwire port correctly For some reason we endup with…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd937x: set the comp soundwire port correctly For some reason we endup with setting soundwire port for HPHL_COMP and HPHR_COMP as zero, this can potentially result in a memory corruption due to accessing and setting -1 th element of port_map array.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= 82be8c62a38c6a44e64ecb29d7a9b5cb35c6cad4 < abcd537aae3b84c6d10ad147e99a204bcb56b234abcd537aae3b84c6d10ad147e99a204bcb56b234
linuxlinux>= 82be8c62a38c6a44e64ecb29d7a9b5cb35c6cad4 < 1a1ca38392e7e896075afc8905ddaea525ed30f71a1ca38392e7e896075afc8905ddaea525ed30f7
linuxlinux>= 82be8c62a38c6a44e64ecb29d7a9b5cb35c6cad4 < 66a940b1bf48a7095162688332d725ba160154eb66a940b1bf48a7095162688332d725ba160154eb
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.11.0 < 6.12.536.12.53
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
ubuntulinux-aws
ubuntulinux-oracle
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.