CVE-2025-40132 — NULL Pointer Dereference in Linux
Severity
6.2MEDIUM
No vectorEPSS
0.0%
top 94.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback
In create_sdw_dailink() check that sof_end->codec_info->add_sidecar
is not NULL before calling it.
The original code assumed that if include_sidecar is true, the codec
on that link has an add_sidecar callback. But there could be other
codecs on the same link that do not have an add_sidecar callback.
Affected Packages5 packages
▶CVEListV5linux/linuxda5244180281a18c4c7859674fec308514aaf629 — aea038062edfca9c6e5ddcecd4611d5a80113b4e+3